CVE-2014-4759: Medium severity ibm business process manager vulnerability
An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4759?
CVE-2014-4759 has a severity rating that can allow authenticated users to access sensitive information.
How do I fix CVE-2014-4759?
To fix CVE-2014-4759, upgrade to a patched version of IBM Business Process Manager beyond 8.5.5.
Who is affected by CVE-2014-4759?
CVE-2014-4759 affects remote authenticated users of IBM Business Process Manager versions 8.5.x up to 8.5.5.
What types of information are at risk with CVE-2014-4759?
CVE-2014-4759 exposes sensitive document properties to remote authenticated users.
Is CVE-2014-4759 a remote vulnerability?
Yes, CVE-2014-4759 is a remote vulnerability that affects authenticated users.