IBM WebSphere 7.2.0.3 Lombardi Edition

CPE Details

IBM WebSphere 7.2.0.3 Lombardi Edition
7.2.0.3
2019-10-28
18h34 +00:00
2019-10-28
18h34 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:websphere:7.2.0.3:*:*:*:lombardi:*:*:*

Informations

Vendor

ibm

Product

websphere

Version

7.2.0.3

Software Edition

lombardi

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-1848 2018-12-14 15h30 +00:00 IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
6.1
Medium
CVE-2017-1756 2018-03-30 16h00 +00:00 IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
4
Medium
CVE-2016-9693 2017-03-07 16h00 +00:00 IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.
6.1
Medium
CVE-2015-1884 2015-06-28 12h00 +00:00 Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.
4
CVE-2015-0193 2015-05-30 17h00 +00:00 Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL that triggers an error condition.
3.5
CVE-2015-0156 2015-05-25 12h00 +00:00 Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
3.5