CVE-2015-1904: Low severity IBM Business Process Manager vulnerability
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1904?
CVE-2015-1904 is considered a moderate severity vulnerability that allows remote authenticated users to bypass certain access controls.
How do I fix CVE-2015-1904?
To fix CVE-2015-1904, ensure that your IBM Business Process Manager is updated to the latest version as recommended by IBM.
Who is affected by CVE-2015-1904?
CVE-2015-1904 affects users of IBM Business Process Manager versions 8.0.x through 8.5.6.0 when external Enterprise Content Management integration is enabled.
What causes CVE-2015-1904?
CVE-2015-1904 is caused by improper configuration of technical system accounts in the Enterprise Content Management integration.
Are there any workarounds for CVE-2015-1904?
A temporary workaround for CVE-2015-1904 includes disabling external Enterprise Content Management integration until the vulnerability can be addressed.