CVE Vulnerabilities

CVE-2014-6139

Published: Feb 13, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.

Affected Software

NameVendorStart VersionEnd Version
Business_process_managerIbm8.0.1.3 (including)8.0.1.3 (including)
Business_process_managerIbm8.5.0.1 (including)8.5.0.1 (including)
Business_process_managerIbm8.5.5.0 (including)8.5.5.0 (including)

References