cbcvebase.

Ibm Business Process Manager vulnerabilities

89 known vulnerabilities affecting ibm/business_process_manager.

Total CVEs
89
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM69LOW13

Vulnerabilities

Page 4 of 5
CVE-2015-0158P4MEDIUMCVSS 4.3v8.0.0.0v8.0.1.0+6 more2015-03-24
CVE-2015-0158 [MEDIUM] CWE-79 CVE-2015-0158: Cross-site scripting (XSS) vulnerability in the Coach NG framework in IBM Business Process Manager ( Cross-site scripting (XSS) vulnerability in the Coach NG framework in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2020-4446P4MEDIUMCVSS 4.3≥ 8.0.0.0, ≤ 8.0.1.3≥ 8.5.0.0, ≤ 8.5.7.0+1 more2020-05-06
CVE-2020-4446 [MEDIUM] CWE-863 CVE-2020-4446: IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 co IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.
nvd
CVE-2019-4045P4MEDIUMCVSS 4.3≥ 8.5.0.0, ≤ 8.5.0.2v8.5.5.0+3 more2019-04-08
CVE-2019-4045 [MEDIUM] CVE-2019-4045: IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 p IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 provide embedded document management features. Because of a missing restriction in an API, a client might spoof the last modified by value of a document. IBM X-Force ID: 156241.
nvd
CVE-2015-7463P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+13 more2018-03-15
CVE-2015-7463 [MEDIUM] CWE-285 CVE-2015-7463: IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
nvd
CVE-2014-6176P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+10 more2014-12-16
CVE-2014-6176 [MEDIUM] CWE-310 CVE-2014-6176: IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions
nvd
CVE-2017-1765P4MEDIUMCVSS 4.3v8.0.0.0v8.0.1.0+13 more2018-03-30
CVE-2017-1765 [MEDIUM] CWE-200 CVE-2017-1765: IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
nvd
CVE-2015-0106P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+11 more2015-03-24
CVE-2015-0106 [MEDIUM] CWE-79 CVE-2015-0106: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2 Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2021-29751P4MEDIUMCVSS 4.3v8.5.0.0v8.6.0.0+2 more2021-06-28
CVE-2021-29751 [MEDIUM] CVE-2021-29751: IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 c IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.
nvd
CVE-2017-1766P4MEDIUMCVSS 4.3v8.5.5.0v8.5.6.0+6 more2018-03-30
CVE-2017-1766 [MEDIUM] CWE-863 CVE-2017-1766: Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
nvd
CVE-2014-0957P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+10 more2014-07-18
CVE-2014-0957 [MEDIUM] CWE-79 CVE-2014-0957: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebS Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
nvd
CVE-2018-1999P4MEDIUMCVSS 4.3≥ 8.0.0.0, ≤ 8.0.1.3≥ 8.5.0.0, ≤ 8.5.0.2+4 more2019-04-08
CVE-2018-1999 [MEDIUM] CWE-200 CVE-2018-1999: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version inf IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889.
nvd
CVE-2014-6139P4MEDIUMCVSS 4.0v8.0.1.3v8.5.0.1+1 more2015-02-13
CVE-2014-6139 [MEDIUM] CWE-264 CVE-2014-6139: The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote auth The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.
nvd
CVE-2014-6101P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+10 more2014-10-31
CVE-2014-6101 [MEDIUM] CWE-79 CVE-2014-6101: Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manag Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4758P4MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+10 more2014-09-04
CVE-2014-4758 [MEDIUM] CWE-264 CVE-2014-4758: IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow re IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
nvd
CVE-2015-1904P4LOWCVSS 3.5v8.0.0.0v8.0.1.0+7 more2015-08-01
CVE-2015-1904 [LOW] CWE-264 CVE-2015-1904: IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5 IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) uploa
nvd
CVE-2015-1906P4LOWCVSS 3.5v7.5.0.0v7.5.0.1+12 more2015-07-21
CVE-2015-1906 [LOW] CWE-79 CVE-2015-1906: Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4802P4MEDIUMCVSS 4.0v8.0.0.0v8.0.1.0+6 more2014-10-07
CVE-2014-4802 [MEDIUM] CWE-264 CVE-2014-4802: The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search.
nvd
CVE-2014-8914P4LOWCVSS 3.5v8.0.0.0v8.0.1.0+6 more2015-01-21
CVE-2014-8914 [LOW] CVE-2014-8914: Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 t Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.
nvd
CVE-2015-0156P4LOWCVSS 3.5v7.5.0.0v7.5.0.1+12 more2015-05-25
CVE-2015-0156 [LOW] CWE-79 CVE-2015-0156: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2 Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6173P4LOWCVSS 3.5v8.0.0.0v8.0.1.0+6 more2014-12-19
CVE-2014-6173 [LOW] CWE-79 CVE-2014-6173: Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (B Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
Ibm Business Process Manager vulnerabilities | cvebase