IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://www-304.ibm.com/support/docview.wss?uid=swg21694940 | vendor advisory |
http://www.securityfocus.com/bid/73274 | third party advisory vdb entry |