Vulnerability Bulletins |
IBM Security Bulletin: Insufficient authorization check in IBM Business Process Manager (BPM) Search REST API (CVE-2014-6139) |
|
| Affected software | IBM |
|
Using the Search REST API, non-administrative users can search for task and process instances that they are not allowed to see by specifying a parameter that should be available only to administrative users. CVE(s): CVE-2014-6139 Affected product(s) and affected version(s): IBM Business Process Manager Standard V8.0.x 8.5.x IBM Business Process Manager Express V8.0.x 8.5.x IBM Business Process Manager Advanced V8.0.x 8.5.x Refer to the following reference URLs for remediation and More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_insufficient_authorization_check_in_ibm_business_process_manager_bpm_search_rest_api_cve_2014_6139?lang=en_us |
|






