CVE-2015-0110
Last modified
CVE-2015-0110 is a vulnerability of currently unknown severity. IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Business Process Manager | 7.5.0.0 |
| Ibm | Business Process Manager | 7.5.0.1 |
| Ibm | Business Process Manager | 7.5.1.0 |
| Ibm | Business Process Manager | 7.5.1.1 |
| Ibm | Business Process Manager | 7.5.1.2 |
| Ibm | Business Process Manager | 8.0.0.0 |
| Ibm | Business Process Manager | 8.0.1.0 |
| Ibm | Business Process Manager | 8.0.1.1 |
| Ibm | Business Process Manager | 8.0.1.2 |
| Ibm | Business Process Manager | 8.0.1.3 |
| Ibm | Business Process Manager | 8.5.0.0 |
| Ibm | Business Process Manager | 8.5.0.1 |
| Ibm | Business Process Manager | 8.5.5.0 |
| Ibm | Websphere Application Server | 7.2.0.0 |
| Ibm | Websphere Application Server | 7.2.0.1 |
| Ibm | Websphere Application Server | 7.2.0.2 |
| Ibm | Websphere Application Server | 7.2.0.3 |
| Ibm | Websphere Application Server | 7.2.0.4 |
| Ibm | Websphere Application Server | 7.2.0.5 |
References
- http://www.securityfocus.com/bid/73274Third Party Advisory, VDB Entry
- https://www-304.ibm.com/support/docview.wss?uid=swg21694940Vendor Advisory
- http://www.securityfocus.com/bid/73274Third Party Advisory, VDB Entry
- https://www-304.ibm.com/support/docview.wss?uid=swg21694940Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0110?
How severe is CVE-2015-0110?
How do I fix CVE-2015-0110?
Are you affected by CVE-2015-0110?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
