Show filters
245 Total Results
Displaying 141-150 of 245
Sort by:
Attacker Value
Unknown
CVE-2015-7463
Disclosure Date: March 15, 2018 (last updated November 26, 2024)
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
0
Attacker Value
Unknown
CVE-2018-2400
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2018-2366
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.
0
Attacker Value
Unknown
CVE-2018-2401
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.
0
Attacker Value
Unknown
CVE-2017-5801
Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.
0
Attacker Value
Unknown
CVE-2015-3618
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
0
Attacker Value
Unknown
CVE-2017-1769
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
0
Attacker Value
Unknown
CVE-2017-1494
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
0
Attacker Value
Unknown
CVE-2017-16681
Disclosure Date: December 12, 2017 (last updated November 26, 2024)
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.
0
Attacker Value
Unknown
CVE-2017-16684
Disclosure Date: December 12, 2017 (last updated November 26, 2024)
SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity.
0