CVE Vulnerabilities

CVE-2014-4844

Published: Dec 17, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit.

Affected Software

Name Vendor Start Version End Version
Business_process_manager Ibm 7.5.0.0 (including) 7.5.0.0 (including)
Business_process_manager Ibm 7.5.0.1 (including) 7.5.0.1 (including)
Business_process_manager Ibm 7.5.1.0 (including) 7.5.1.0 (including)
Business_process_manager Ibm 7.5.1.1 (including) 7.5.1.1 (including)
Business_process_manager Ibm 7.5.1.2 (including) 7.5.1.2 (including)
Business_process_manager Ibm 8.0.0.0 (including) 8.0.0.0 (including)
Business_process_manager Ibm 8.0.1.0 (including) 8.0.1.0 (including)
Business_process_manager Ibm 8.0.1.1 (including) 8.0.1.1 (including)
Business_process_manager Ibm 8.0.1.2 (including) 8.0.1.2 (including)
Business_process_manager Ibm 8.5.0.0 (including) 8.5.0.0 (including)
Business_process_manager Ibm 8.5.0.1 (including) 8.5.0.1 (including)
Business_process_manager Ibm 8.5.5.0 (including) 8.5.5.0 (including)

References