CVE-2015-7463: Medium severity ibm business process manager vulnerability
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7463?
CVE-2015-7463 has a severity rating designated as high due to its potential to allow remote authenticated users to delete process and task data.
How do I fix CVE-2015-7463?
To fix CVE-2015-7463, it is advised to apply the latest cumulative fixes provided by IBM for the affected versions of IBM Business Process Manager.
Which versions of IBM Business Process Manager are affected by CVE-2015-7463?
CVE-2015-7463 affects IBM Business Process Manager versions 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2.
Can CVE-2015-7463 be exploited remotely?
Yes, CVE-2015-7463 can be exploited remotely by authenticated users due to improper authorization checks.
What type of data can be deleted due to CVE-2015-7463?
CVE-2015-7463 allows the deletion of process and task data within the IBM Business Process Manager.