Vulnerability Description
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Business Process Manager | 8.0.0.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR55152Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21978058Vendor Advisory
- http://www.securitytracker.com/id/1035175
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR55152Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21978058Vendor Advisory
- http://www.securitytracker.com/id/1035175
FAQ
What is CVE-2016-0227?
CVE-2016-0227 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6...
How severe is CVE-2016-0227?
CVE-2016-0227 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0227?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Business Process Manager.