CVE-2014-3087
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity…
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.33% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/business process manager · ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/60752
- http://secunia.com/advisories/60755
- http://secunia.com/advisories/60757
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR50616Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21679726Patch, Vendor Advisory
- http://www.securityfocus.com/bid/69264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94112
- http://secunia.com/advisories/60752
- http://secunia.com/advisories/60755
- http://secunia.com/advisories/60757
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR50616Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21679726Patch, Vendor Advisory
- http://www.securityfocus.com/bid/69264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94112
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.