CVE-2015-1884: Path Traversal
Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1884?
CVE-2015-1884 has a CVSS score indicating it is a high severity vulnerability.
How do I fix CVE-2015-1884?
To fix CVE-2015-1884, you should apply the appropriate patches and updates provided by IBM for the affected versions.
What systems are affected by CVE-2015-1884?
CVE-2015-1884 affects multiple versions of IBM Business Process Manager and IBM WebSphere Lombardi Edition.
Can CVE-2015-1884 be exploited remotely?
Yes, CVE-2015-1884 can be exploited by remote authenticated users to read arbitrary files.
Are there any workarounds for CVE-2015-1884?
Temporary mitigation for CVE-2015-1884 includes restricting access privileges for authenticated users to sensitive directories.