CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
Percentile
39.8%
Sensitive information about the application server is revealed during snapshot export in IBM Business Process Manager.
CVEID: CVE-2017-1765 DESCRIPTION: IBM Business Process Manager could allow an authenticated user with special privileges to reveal sensitive information about the application server.
CVSS Base Score: 3.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/136150> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)
- IBM Business Process Manager V8.0.0.0 through V8.0.1.3
- IBM Business Process Manager V8.5.0.0 through V8.5.0.2
- IBM Business Process Manager V8.5.5.0
- IBM Business Process Manager V8.5.6.0 through V8.5.6.0 CF2
- IBM Business Process Manager V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06
- IBM Business Process Manager V8.6.0.0
- IBM Business Process Manager Enterprise Service Bus V8.6.0.0
The recommended solution is to apply the Interim Fix (iFix) or Cumulative Fix (CF) containing APAR JR58727 as soon as practical:
For IBM BPM V8.6.0.0 (released 2017.09)
For IBM BPM V8.5.7.0 through V8.5.7.0 CF 2017.06
For IBM BPM V8.5.6.0 through V8.5.6.0 CF2
For IBM BPM V8.5.5.0
For IBM BPM V8.5.0.0 through V8.5.0.2
For IBM BPM V8.0.0.0 through V8.0.1.3
As IBM Business Process Manager V8.0 is out of general support, customers with a support extension contract can contact IBM support to request the fix.
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | business_process_manager | 8.6 | cpe:2.3:a:ibm:business_process_manager:8.6:*:*:*:*:*:*:* |
ibm | business_process_manager | 8.5.7. | cpe:2.3:a:ibm:business_process_manager:8.5.7.:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 201706 | cpe:2.3:a:ibm:business_process_manager:201706:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 201703 | cpe:2.3:a:ibm:business_process_manager:201703:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 201612 | cpe:2.3:a:ibm:business_process_manager:201612:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 201609 | cpe:2.3:a:ibm:business_process_manager:201609:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 201606 | cpe:2.3:a:ibm:business_process_manager:201606:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 8.5.7 | cpe:2.3:a:ibm:business_process_manager:8.5.7:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 8.5.6.2 | cpe:2.3:a:ibm:business_process_manager:8.5.6.2:*:*:*:advanced:*:*:* |
ibm | business_process_manager | 8.5.6.1 | cpe:2.3:a:ibm:business_process_manager:8.5.6.1:*:*:*:advanced:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
Percentile
39.8%