Show filters
245 Total Results
Displaying 151-160 of 245
Sort by:
Attacker Value
Unknown

CVE-2017-1628

Disclosure Date: November 27, 2017 (last updated November 26, 2024)
IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
0
Attacker Value
Unknown

CVE-2017-14995

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
0
Attacker Value
Unknown

CVE-2017-1527

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.
0
Attacker Value
Unknown

CVE-2017-1425

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478.
0
Attacker Value
Unknown

CVE-2017-1530

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.
0
Attacker Value
Unknown

CVE-2017-1531

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.
0
Attacker Value
Unknown

CVE-2017-1539

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
0
Attacker Value
Unknown

CVE-2017-1346

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
0
Attacker Value
Unknown

CVE-2017-1424

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.
0
Attacker Value
Unknown

CVE-2017-14651

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.