The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21959052 | patch vendor advisory |
http://www.securitytracker.com/id/1032972 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1JR53356 | patch vendor advisory |
http://www.securityfocus.com/bid/75536 | vdb entry |