Due to insufficient user input escaping IBM Business Process Manager dashboards are vulnerable to Cross-Site scripting.
CVEID: CVE-2015-4955**
DESCRIPTION:** IBM Business Process Manager is vulnerable to reflected cross-site scripting, which is caused by the improper escaping of user-supplied input. A remote attacker might exploit this vulnerability using a specially crafted URL to execute a script in a user’s web browser within the security context of the hosting web site after the URL is clicked. An attacker might use this vulnerability to steal the user’s cookie-based authentication credentials.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105201 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Install the interim fixes for APAR JR52696 and JR54007 as appropriate for your current IBM Business Process Manager version.
For V8.5.5.0, interim fix JR53179 contains the fix for interim fix JR52696.
Please note that the fixes for 8.5.6.0 is included in Cumulative Fix 1, see Product maintenance strategy for IBM Business Process Manager V8.5.6 and V8.5.7.
None