CVE-2015-7454
Last modified
CVE-2015-7454 is a vulnerability of currently unknown severity. Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Process Server | 6.1.2 |
| Ibm | Websphere Process Server | 6.1.2.1 |
| Ibm | Websphere Process Server | 6.1.2.2 |
| Ibm | Websphere Process Server | 6.1.2.3 |
| Ibm | Websphere Process Server | 6.2 |
| Ibm | Websphere Process Server | 6.2.0.1 |
| Ibm | Websphere Process Server | 6.2.0.2 |
| Ibm | Websphere Process Server | 6.2.0.3 |
| Ibm | Websphere Process Server | 7.0 |
| Ibm | Websphere Process Server | 7.0.0.1 |
| Ibm | Websphere Process Server | 7.0.0.2 |
| Ibm | Websphere Process Server | 7.0.0.3 |
| Ibm | Websphere Process Server | 7.0.0.4 |
| Ibm | Websphere Process Server | 7.0.0.5 |
| Ibm | Business Process Manager | 7.5.0.0 |
| Ibm | Business Process Manager | 7.5.0.1 |
| Ibm | Business Process Manager | 7.5.1.0 |
| Ibm | Business Process Manager | 7.5.1.1 |
| Ibm | Business Process Manager | 7.5.1.2 |
| Ibm | Business Process Manager | 8.0.0.0 |
| Ibm | Business Process Manager | 8.0.1.0 |
| Ibm | Business Process Manager | 8.0.1.1 |
| Ibm | Business Process Manager | 8.0.1.2 |
| Ibm | Business Process Manager | 8.0.1.3 |
| Ibm | Business Process Manager | 8.5.0.0 |
| Ibm | Business Process Manager | 8.5.0.1 |
| Ibm | Business Process Manager | 8.5.0.2 |
| Ibm | Business Process Manager | 8.5.5.0 |
| Ibm | Business Process Manager | 8.5.6.0 |
| Ibm | Business Process Manager | 8.5.6.1 |
| Ibm | Business Process Manager | 8.5.6.2 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21972005Patch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21972005Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7454?
How severe is CVE-2015-7454?
How do I fix CVE-2015-7454?
Are you affected by CVE-2015-7454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
