Vulnerability Name: | CVE-2015-0110 (CCN-99630) | ||||||||||||
Assigned: | 2014-11-18 | ||||||||||||
Published: | 2015-03-13 | ||||||||||||
Updated: | 2017-09-26 | ||||||||||||
Summary: | IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-284 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-0110 Source: CCN Type: IBM Security Bulletin 1694940 Internal service types can be invoked in IBM Business Process Manager (BPM) and WebSphere Lombardi Edition (WLE) Process Portal (CVE-2015-0110) Source: BID Type: Third Party Advisory, VDB Entry 73274 Source: XF Type: UNKNOWN ibm-bpm-cve20150110-sec-bypass(99630) Source: CONFIRM Type: Vendor Advisory https://www-304.ibm.com/support/docview.wss?uid=swg21694940 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
BACK |