Vulnerability Details CVE-2014-0957
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.9%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-0957
-
cpe:2.3:a:ibm:business_process_manager:7.5.0.0
-
cpe:2.3:a:ibm:business_process_manager:7.5.0.1
-
cpe:2.3:a:ibm:business_process_manager:7.5.1.0
-
cpe:2.3:a:ibm:business_process_manager:7.5.1.1
-
cpe:2.3:a:ibm:business_process_manager:7.5.1.2
-
cpe:2.3:a:ibm:business_process_manager:8.0.0.0
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.0
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.1
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.2
-
cpe:2.3:a:ibm:business_process_manager:8.5.0.0
-
cpe:2.3:a:ibm:business_process_manager:8.5.0.1
-
cpe:2.3:a:ibm:business_process_manager:8.5.5.0
-
cpe:2.3:a:ibm:websphere_application_server:7.2