Vulnerability Bulletins |
IBM Security Bulletin: Internal service types can be invoked in IBM Business Process Manager (BPM) and WebSphere Lombardi Edition (WLE) Process Portal (CVE-2015-0110) |
|
| Affected software | IBM |
|
When invoking a service using the executeServiceByName URL, there is no access restriction based on the service type and services that were meant for internal use only are available for authenticated users. CVE(s): CVE-2015-0110 Affected product(s) and affected version(s): IBM Business Process Manager Standard V7.5.x, 8.0.x, 8.5.x IBM Business Process Manager Express V7.5.x, 8.0.x, 8.5.x IBM Business Process Manager Advanced V7.5.x, 8.0.x, 8.5.x WebSphere Lombardi Edition 7.2.x More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_internal_service_types_can_be_invoked_in_ibm_business_process_manager_bpm_and_websphere_lombardi_edition_wle_process_portal_cve_2015_0110?lang=en_us |
|






