CVE-2015-1904
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account…
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/business process manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR53209Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21960293Patch, Vendor Advisory
- http://www.securitytracker.com/id/1033159
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR53209Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21960293Patch, Vendor Advisory
- http://www.securitytracker.com/id/1033159
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.