CVE-2014-0908

The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail notifications, or modify task assignments via REST API calls.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:business_process_manager:7.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:7.5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:7.5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:7.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:7.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:8.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_process_manager:8.5.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:03

Type Values Removed Values Added
References () http://www-01.ibm.com/support/docview.wss?uid=swg1JR49505 - () http://www-01.ibm.com/support/docview.wss?uid=swg1JR49505 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21669330 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21669330 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/91870 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/91870 -

Information

Published : 2014-04-10 23:55

Updated : 2024-11-21 02:03


NVD link : CVE-2014-0908

Mitre link : CVE-2014-0908

CVE.ORG link : CVE-2014-0908


JSON object : View

Products Affected

ibm

  • business_process_manager
CWE
CWE-264

Permissions, Privileges, and Access Controls