Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/136151 | vdb entry vendor advisory |
http://www.ibm.com/support/docview.wss?uid=swg22011866 | patch vendor advisory |