3.5
CVSSv2

CVE-2015-1904

Published: 01/08/2015 Updated: 21/09/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

IBM Business Process Manager (BPM) 8.0.x up to and including 8.0.1.3, 8.5.0 up to and including 8.5.0.1, 8.5.5 up to and including 8.5.5.0, and 8.5.6 up to and including 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm business process manager 8.0.0.0

ibm business process manager 8.0.1.0

ibm business process manager 8.0.1.2

ibm business process manager 8.5.0.1

ibm business process manager 8.0.1.1

ibm business process manager 8.0.1.3

ibm business process manager 8.5.0.0

ibm business process manager 8.5.5.0

ibm business process manager 8.5.6.0