CVE-2014-6139: Medium severity ibm business process manager vulnerability
The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6139?
CVE-2014-6139 is rated as a High severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2014-6139?
To fix CVE-2014-6139, update your IBM Business Process Manager to a version that includes the security patches addressing this vulnerability.
Who is affected by CVE-2014-6139?
CVE-2014-6139 affects remote authenticated users of IBM Business Process Manager versions 8.0.1.3, 8.5.0.1, and 8.5.5.0.
What impact does CVE-2014-6139 have?
The impact of CVE-2014-6139 is the potential for authenticated users to bypass access controls and access unauthorized task and process instances.
Is there a workaround for CVE-2014-6139?
Currently, there are no documented workarounds for CVE-2014-6139; the recommended action is to apply the necessary updates.