First published: Fri Feb 13 2015(Updated: )
The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6139 is rated as a High severity vulnerability due to its potential to allow unauthorized access to sensitive information.
To fix CVE-2014-6139, update your IBM Business Process Manager to a version that includes the security patches addressing this vulnerability.
CVE-2014-6139 affects remote authenticated users of IBM Business Process Manager versions 8.0.1.3, 8.5.0.1, and 8.5.5.0.
The impact of CVE-2014-6139 is the potential for authenticated users to bypass access controls and access unauthorized task and process instances.
Currently, there are no documented workarounds for CVE-2014-6139; the recommended action is to apply the necessary updates.