CVE-2014-0957
IBM Business Process Manager - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
References (4)
Scores
EPSS
0.0028
EPSS Percentile
51.0%
Details
CWE
CWE-79
Status
published
Products (14)
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
... and 4 more
Published
Jul 18, 2014
Tracked Since
Feb 18, 2026