CVE-2014-4844: Medium severity ibm business process manager vulnerability
The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4844?
CVE-2014-4844 has been categorized with a medium severity due to its potential access control bypass for authenticated users.
How do I fix CVE-2014-4844?
To mitigate CVE-2014-4844, upgrade to a patched version of IBM Business Process Manager that addresses this vulnerability.
What versions of IBM Business Process Manager are affected by CVE-2014-4844?
CVE-2014-4844 impacts versions 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.
Who can exploit CVE-2014-4844?
CVE-2014-4844 can be exploited by remote authenticated users who have access to project actions.
What types of access can be bypassed due to CVE-2014-4844?
CVE-2014-4844 allows bypassing intended access restrictions related to process applications and toolkits.