CVE-2014-4758: Medium severity ibm business process manager vulnerability
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4758?
CVE-2014-4758 is classified as a Moderate severity vulnerability due to the potential for unauthorized access by authenticated users.
How do I fix CVE-2014-4758?
To fix CVE-2014-4758, apply the latest patches and updates provided by IBM for affected versions of Business Process Manager and WebSphere Lombardi Edition.
Who is impacted by CVE-2014-4758?
CVE-2014-4758 impacts remote authenticated users of IBM Business Process Manager and WebSphere Lombardi Edition, allowing them to bypass access restrictions.
What systems are affected by CVE-2014-4758?
CVE-2014-4758 affects IBM Business Process Manager versions 7.5.x to 8.5.5 and WebSphere Lombardi Edition version 7.2.x.
What actions should be taken if CVE-2014-4758 is detected in my system?
If CVE-2014-4758 is detected, prioritize updating the affected systems and reviewing access logs for any unauthorized usage.