Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x up to and including 8.0.1.3 and 8.5.x up to and including 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm business process manager 8.0.0.0 |
||
ibm business process manager 8.0.1.0 |
||
ibm business process manager 8.5.0.1 |
||
ibm business process manager 8.5.5.0 |
||
ibm business process manager 8.0.1.1 |
||
ibm business process manager 8.0.1.2 |
||
ibm business process manager 8.0.1.3 |
||
ibm business process manager 8.5.0.0 |