IBM Business Process Manager that is bundled with IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition has identified a vulnerability.
IBM Cloud Orchestrator V2.4 has addressed this vulnerability. It includes IBM Business Process Manager V8.5.6 CF2.
CVEID: CVE-2014-8912** *DESCRIPTION: IBM WebSphere Portal and other products could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to resources located within web applications. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99253 for the current score
CVSS Environmental Score: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Affected Principal Product and Version
| Affected Supporting Product and Version
—|—
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition V2.4, V2.4.0.1, V2.4.0.2, V2.4.0.3| IBM Business Process Manager V8.5.5 through V8.5.6
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition V2.3, V2.3.0.1| IBM Business Process Manager V8.5.0.1
Product
| VRMF|Remediation/First Fix
—|—|—
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition| V2.4, V2.4.0.1, V2.4.0.2, V2.4.0.3| For 2.4 versions, IBM recommends upgrading to Fix Pack 4 (2.4.0.4) of IBM Cloud Orchestrator.
https://www-01.ibm.com/support/docview.wss?uid=swg2C4000049
IBM Cloud Orchestrator and Cloud Orchestrator Enterprise Edition | V2.3, V2.3.0.1| Contact IBM Support
None