Vulnerability Bulletins |
IBM Security Bulletin: XML External Entity Processing in Castor might affect IBM Business Process Manager (CVE-2014-3004) |
|
| Affected software | IBM |
|
An XML External Entity Processing vulnerability has been reported for the Castor open source library that is used in IBM Business Process Manager (BPM). CVE(s): CVE-2014-3004 Affected product(s) and affected version(s): IBM Business Process Manager Standard V7.5.x, 8.0.x 8.5.x IBM Business Process Manager Express V7.5.x, 8.0.x 8.5.x IBM Business Process Manager Advanced V7.5.x, 8.0.x 8.5.x Refer to the following reference URLs for remediation and additional vulnerability More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_xml_external_entity_processing_in_castor_might_affect_ibm_business_process_manager_cve_2014_3004?lang=en_us |
|






