IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified JSP diagnostic page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/60614 | third party advisory |
http://www.securitytracker.com/id/1030666 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1JR50760 | patch vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21679976 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/93822 | vdb entry |