First published: Wed Dec 17 2014(Updated: )
Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6182 has a medium severity rating allowing authenticated users to access sensitive files.
To fix CVE-2014-6182, upgrade to a patched version of IBM Business Process Manager beyond 8.0.1.3 and 8.5.5.
CVE-2014-6182 affects users of IBM Business Process Manager versions 8.0.x up to 8.0.1.3 and 8.5.x up to 8.5.5.
CVE-2014-6182 can be exploited via a directory traversal attack through crafted URLs.
CVE-2014-6182 was published on September 24, 2014.