IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/108393 | vdb entry vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21973442 | patch vendor advisory |