CVE-2015-1961: Critical severity ibm business process manager vulnerability
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1961?
CVE-2015-1961 has a severity rating of Medium, as it allows remote authenticated users to bypass access restrictions and execute arbitrary JavaScript code.
How do I fix CVE-2015-1961?
To fix CVE-2015-1961, you should upgrade your IBM Business Process Manager to a version that addresses this vulnerability.
Which software versions are affected by CVE-2015-1961?
CVE-2015-1961 affects IBM Business Process Manager versions 7.5.x up to 7.5.1.2, 8.0.x up to 8.0.1.3, and versions 8.5.0 to 8.5.6.0.
What types of attacks can CVE-2015-1961 facilitate?
CVE-2015-1961 can facilitate unauthorized access and execution of arbitrary JavaScript code on the server, potentially leading to further exploits.
Who is primarily at risk from CVE-2015-1961?
Organizations using vulnerable versions of IBM Business Process Manager with remote authenticated users have the primary risk from CVE-2015-1961.