Lucene search

K
ibmIBMB56B4019CDC0B63F0DB3520A65E329C518A5A6C6B2986F7AB8AC8749EFAF4340
HistorySep 15, 2022 - 6:13 p.m.

Security Bulletin: WebSphere Process Server (WPS) / IBM Business Process Manager (BPM) – Cross-site scripting security vulnerability in local help system

2022-09-1518:13:52
www.ibm.com
5
cross-site scripting
ibm websphere
business process manager
vulnerability
cve-2013-5449
ibm eclipse help
cvss
remediation
websphere process server
business process manager standard
business process manager express
business process manager advanced
workarounds

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

55.1%

Summary

A Cross-site scripting security vulnerability exists in the IBM Eclipse Help System, which is used to provide the product information centers for the IBM WebSphere Process Server and IBM Business Process Manager products. For more details about Cross-site Scripting (XSS), see the Open Web Application Security Project (OWASP) Wiki link, which is listed under Related URLs.

Vulnerability Details

A remote attacker might exploit this vulnerability using a specially crafted URL to execute a script in a web browser within the security context of the hosting web site after the URL is clicked. An attacker might use this vulnerability to steal the cookie-based authentication credentials for a user.

CVEID: CVE-2013-5449
Description: IBM Eclipse Help System (IEHS) cross-site scripting
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/88056&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

  • WebSphere Process Server V6.1.2, 6.2.x, 7.0.x
  • WebSphere Process Server on z/OS V6.2.x, 7.0.x
  • WebSphere Process Server Hypervisor Edition for Red Hat Enterprise Linux Server for x86 (32-bit) V7.0.0
  • WebSphere Process Server Hypervisor Edition for Novell SUSE Linux Enterprise Server for x86 (32-bit) V6.2.x, 7.0.x
  • WebSphere Process Server Hypervisor Edition for Novell SUSE Linux Enterprise Server for System z V6.2.x, 7.0.x
  • IBM Business Process Manager Standard V7.5.x
  • IBM Business Process Manager Express V7.5.x
  • IBM Business Process Manager Advanced V7.5.x

Remediation/Fixes

Download the latest local help content, which is available through the following links. The local help content downloads are full packages, which include the updated framework that fixes this vulnerability.

Workarounds and Mitigations

Uninstall the BSpaceHelp_<DeploymentTarget> and IBM_BPM_Help_<DeploymentTarget> local help applications and refer to the online versions of the product information centers.

Affected configurations

Vulners
Node
ibmbusiness_process_managerMatch7.5.1.1advanced
OR
ibmbusiness_process_managerMatch7.5.1advanced
OR
ibmbusiness_process_managerMatch7.5.0.1advanced
OR
ibmbusiness_process_managerMatch7.5advanced
OR
ibmwebsphere_process_serverMatch7.0
OR
ibmwebsphere_process_serverMatch7.0
OR
ibmwebsphere_process_serverMatch6.2
OR
ibmwebsphere_process_serverMatch7.0
OR
ibmwebsphere_process_serverMatch6.2
OR
ibmwebsphere_process_serverMatch7.0.0.5
OR
ibmwebsphere_process_serverMatch7.0.0.4
OR
ibmwebsphere_process_serverMatch7.0.0.3
OR
ibmwebsphere_process_serverMatch7.0.0.2
OR
ibmwebsphere_process_serverMatch7.0.0.1
OR
ibmwebsphere_process_serverMatch7.0
OR
ibmwebsphere_process_serverMatch6.2.0.3
OR
ibmwebsphere_process_serverMatch6.2.0.2
OR
ibmwebsphere_process_serverMatch6.2.0.1
OR
ibmwebsphere_process_serverMatch6.2
OR
ibmwebsphere_process_serverMatch6.1.2.3
OR
ibmwebsphere_process_serverMatch6.1.2.2
OR
ibmwebsphere_process_serverMatch6.1.2.1
OR
ibmwebsphere_process_serverMatch6.1.2
OR
ibmbusiness_process_managerMatch7.5.1.1standard
OR
ibmbusiness_process_managerMatch7.5.1standard
OR
ibmbusiness_process_managerMatch7.5.0.1standard
OR
ibmbusiness_process_managerMatch7.5standard
OR
ibmbusiness_process_managerMatch7.5.1.1express
OR
ibmbusiness_process_managerMatch7.5.1express
OR
ibmbusiness_process_managerMatch7.5.0.1express
OR
ibmbusiness_process_managerMatch7.5express

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

55.1%

Related for B56B4019CDC0B63F0DB3520A65E329C518A5A6C6B2986F7AB8AC8749EFAF4340