Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3) portal/jsp/viewAdHocReportWizard.do, or (4) rest/bpm/wle/v1/process.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2013-07-06T10:00:00

Updated: 2024-08-06T14:33:05.203Z

Reserved: 2012-12-16T00:00:00

Link: CVE-2013-0581

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-07-06T13:57:33.293

Modified: 2017-08-29T01:33:07.247

Link: CVE-2013-0581

cve-icon Redhat

No data.