Vulnerability Name: | CVE-2014-0908 (CCN-91870) | ||||||||
Assigned: | 2014-04-04 | ||||||||
Published: | 2014-04-04 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail notifications, or modify task assignments via REST API calls. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0908 Source: CCN Type: SA57761 IBM Business Process Manager User Attributes REST API Authorisation Security Issue Source: AIXAPAR Type: UNKNOWN JR49505 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21669330 Source: CCN Type: BID-66679 IBM Business Process Manager Authorization Bypass Vulnerability Source: XF Type: UNKNOWN ibm-bpm-cve20140908-priv-escalation(91870) Source: XF Type: UNKNOWN ibm-bpm-cve20140908-priv-escalation(91870) Source: CCN Type: IBM Security Bulletin 1669330 Missing authorization concept for IBM Business Process Manager (BPM) User Attributes CVE-2014-0908 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |