{"api_version":"1","generated_at":"2026-07-23T09:31:54+00:00","cve":"CVE-2014-8914","urls":{"html":"https://cve.report/CVE-2014-8914","api":"https://cve.report/api/cve/CVE-2014-8914.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-8914","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-8914"},"summary":{"title":"CVE-2014-8914","description":"Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.","state":"PUBLISHED","assigner":"ibm","published_at":"2015-01-21 15:17:04","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99285","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99285","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21693239","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21693239","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Cross-site scripting vulnerabilities in IBM Business Process Manager (BPM) Process Portal (CVE-2014-8913, CVE-2014-8914)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/62205","name":"http://secunia.com/advisories/62205","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA62205 - IBM Business Process Manager Cross-Site Scripting Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR52103","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR52103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM JR52103: WITH JR49924 FIX INSTALLED, SETTING THE START PAGE TO A DASHBOARD IN IBM PROCESS PORTAL DOES NOT WORK CORRECTLY","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031614","name":"http://www.securitytracker.com/id/1031614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Business Process Manager Input Validation Flaws in Process Portal Permit Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR51836","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR51836","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM JR51836: SECURITY APAR CVE-2014-8914 - SCRIPT INJECTION VULNERABILITY OCCURS WHEN YOU START A PROCESS IN IBM PROCESS PORTAL","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-8914","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8914","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.0.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.0.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.0.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"business_process_manager","cpe6":"8.5.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:33:13.146Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"62205","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/62205"},{"name":"JR51836","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR51836"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21693239"},{"name":"ibm-bpm-cve20148914-xss(99285)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99285"},{"name":"1031614","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031614"},{"name":"JR52103","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR52103"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-01-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"62205","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/62205"},{"name":"JR51836","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR51836"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21693239"},{"name":"ibm-bpm-cve20148914-xss(99285)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99285"},{"name":"1031614","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031614"},{"name":"JR52103","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR52103"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2014-8914","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"62205","refsource":"SECUNIA","url":"http://secunia.com/advisories/62205"},{"name":"JR51836","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR51836"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21693239","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21693239"},{"name":"ibm-bpm-cve20148914-xss(99285)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99285"},{"name":"1031614","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031614"},{"name":"JR52103","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1JR52103"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2014-8914","datePublished":"2015-01-21T11:00:00.000Z","dateReserved":"2014-11-14T00:00:00.000Z","dateUpdated":"2024-08-06T13:33:13.146Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-01-21 15:17:04","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"161542A0-E919-4105-AD4F-C881ACF8D26B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:*:*:*:*","matchCriteriaId":"AF8D1DC9-CB5E-4627-8689-B5FA7C5DE1C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:*:*:*:*","matchCriteriaId":"32504DEB-7391-4452-BA2E-409959B24222"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:*:*:*:*","matchCriteriaId":"D8F74820-DF10-499E-AF7A-93AC285843D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.0.1.3:*:*:*:*:*:*:*","matchCriteriaId":"4C12274F-495C-4E81-A317-E66916B0A2F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"989C89DF-C6CB-45C9-9592-30A83896BD71"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"783C2592-9669-4C75-9E63-C834482F6F8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:business_process_manager:8.5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"7021B830-3EE4-446D-8D87-BBD2097A023E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"8914","Ordinal":"1","Title":"CVE-2014-8914","CVE":"CVE-2014-8914","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"8914","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.","Type":"Description","Title":"CVE-2014-8914"},{"CveYear":"2014","CveId":"8914","Ordinal":"2","NoteData":"2015-01-21","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"8914","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}