Show filters
245 Total Results
Displaying 141-150 of 245
Sort by:
Attacker Value
Unknown

CVE-2015-7463

Disclosure Date: March 15, 2018 (last updated November 26, 2024)
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
0
Attacker Value
Unknown

CVE-2018-2400

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown

CVE-2018-2366

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.
0
Attacker Value
Unknown

CVE-2018-2401

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.
0
Attacker Value
Unknown

CVE-2017-5801

Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.
0
Attacker Value
Unknown

CVE-2015-3618

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
0
Attacker Value
Unknown

CVE-2017-1769

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
0
Attacker Value
Unknown

CVE-2017-1494

Disclosure Date: December 20, 2017 (last updated November 26, 2024)
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
0
Attacker Value
Unknown

CVE-2017-16681

Disclosure Date: December 12, 2017 (last updated November 26, 2024)
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.
0
Attacker Value
Unknown

CVE-2017-16684

Disclosure Date: December 12, 2017 (last updated November 26, 2024)
SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity.
0