CVE-2015-1905: Medium severity IBM Business Process Manager vulnerability
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1905?
CVE-2015-1905 has a medium severity rating due to its potential for unauthorized access by authenticated users.
How do I fix CVE-2015-1905?
To mitigate CVE-2015-1905, users should apply the latest IBM Business Process Manager patches that address this vulnerability.
What versions of IBM Business Process Manager are affected by CVE-2015-1905?
CVE-2015-1905 affects IBM Business Process Manager versions 7.5.x up to 7.5.1.2, 8.0.x up to 8.0.1.3, and 8.5.x up to 8.5.6.0.
What kind of vulnerability is CVE-2015-1905?
CVE-2015-1905 is an access control vulnerability that allows remote authenticated users to bypass security restrictions.
Are there known exploits for CVE-2015-1905?
At the time of its disclosure, there were no publicly known exploits for CVE-2015-1905.