CVE Vulnerabilities

CVE-2015-1904

Published: Aug 01, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.

Affected Software

NameVendorStart VersionEnd Version
Business_process_managerIbm8.0.0.0 (including)8.0.0.0 (including)
Business_process_managerIbm8.0.1.0 (including)8.0.1.0 (including)
Business_process_managerIbm8.0.1.1 (including)8.0.1.1 (including)
Business_process_managerIbm8.0.1.2 (including)8.0.1.2 (including)
Business_process_managerIbm8.0.1.3 (including)8.0.1.3 (including)
Business_process_managerIbm8.5.0.0 (including)8.5.0.0 (including)
Business_process_managerIbm8.5.0.1 (including)8.5.0.1 (including)
Business_process_managerIbm8.5.5.0 (including)8.5.5.0 (including)
Business_process_managerIbm8.5.6.0 (including)8.5.6.0 (including)

References