CVE-2015-1904
Last modified
CVE-2015-1904 is a vulnerability of currently unknown severity. IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.. EPSS estimates a 1.42% chance of exploitation in the next 30 days.
Description
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Business Process Manager | 8.0.0.0 |
| Ibm | Business Process Manager | 8.0.1.0 |
| Ibm | Business Process Manager | 8.0.1.1 |
| Ibm | Business Process Manager | 8.0.1.2 |
| Ibm | Business Process Manager | 8.0.1.3 |
| Ibm | Business Process Manager | 8.5.0.0 |
| Ibm | Business Process Manager | 8.5.0.1 |
| Ibm | Business Process Manager | 8.5.5.0 |
| Ibm | Business Process Manager | 8.5.6.0 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR53209Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21960293Patch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR53209Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21960293Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1904?
How severe is CVE-2015-1904?
How do I fix CVE-2015-1904?
Are you affected by CVE-2015-1904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
