Bypassing Access Restrictions on Task-Variable Value Changes in IBM Business Process Manager (BPM)

Bypassing Access Restrictions on Task-Variable Value Changes in IBM Business Process Manager (BPM)

CVE-2015-1905 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors.

Learn more about our Cis Benchmark Audit For Ibm I.