Date published: 2014-12-18T21:59:02.860-05:00
Date last modified: 2017-09-07T21:29:11.340-04:00
CVSS Score: 3.5
Principal attack vector: NETWORK
Reference URL: http://www-01.ibm.com/support/docview.wss?uid=swg1JR50241
Summary: Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 126.96.36.199 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.