CVE-2015-7454
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote…
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere process server · ibm/business process manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR54678
- http://www-01.ibm.com/support/docview.wss?uid=swg21972005Patch, Vendor Advisory
- http://www.securityfocus.com/bid/85089
- http://www.securitytracker.com/id/1035319
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR54678
- http://www-01.ibm.com/support/docview.wss?uid=swg21972005Patch, Vendor Advisory
- http://www.securityfocus.com/bid/85089
- http://www.securitytracker.com/id/1035319
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.