CVE-2014-8914
EUVD-2014-874121.01.2015, 15:17
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.5.0 |
𝑥
= Vulnerable software versions
References