VulnerabilityModified
CVE-2016-0349
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
MEDIUM 6.5EPSS 1.46%
Does this matter?
Lower severity and a low EPSS score (1.46%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/business process manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR55701Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21981094Vendor Advisory
- http://www.securitytracker.com/id/1036185
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR55701Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21981094Vendor Advisory
- http://www.securitytracker.com/id/1036185
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.