PT-2014-6101 · Ibm · Ibm Business Process Manager
Published
2014-09-04
·
Updated
2017-08-29
·
CVE-2014-4759
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Business Process Manager (BPM) versions 8.5.x through 8.5.5
Description
The issue allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results. This is due to an unspecified Ajax service in the Content Management toolkit.
Recommendations
For versions 8.5.x through 8.5.5, consider restricting access to the document-attachment search functionality until a fix is available. As a temporary workaround, limit the ability to read document properties in search results to minimize the risk of sensitive information disclosure.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Business Process Manager