PT-2017-12981 · Ibm · Ibm Business Process Manager

Published

2017-09-25

·

Updated

2017-09-28

·

CVE-2017-1346

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Business Process Manager versions 7.5 through 8.5
Description The issue allows a local user to read files temporarily stored in a folder during offline installs, within a short timespan.
Recommendations For versions 7.5 through 8.5, consider restricting access to the temporary folder used during offline installs to prevent unauthorized reading of files.

Fix

Race Condition

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1346

Affected Products

Ibm Business Process Manager