CVE-2014-0957: IBM Business Process Manager

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.

Affected products

  • IBM Business Process Manager: version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.1.0 only; version 7.5.1.1 only; version 7.5.1.2 only; version 8.0.0.0 only; …
  • IBM WebSphere Application Server: version 7.2 only

Published 2014-07-18. Last modified 2026-06-17.