Lucene search

K
ibmIBM71E3E7D172741F94122AA1369C26CEDDF9D9EFD69EA9D82DCEB29BB70F53E51E
HistoryJun 15, 2018 - 7:01 a.m.

Security Bulletin: Unauthorized disclosure of system information in IBM Business Process Manager (BPM) 8.5.x (CVE-2014-3076)

2018-06-1507:01:08
www.ibm.com
7

EPSS

0.005

Percentile

76.0%

Summary

System information is provided on an unprotected diagnostic page.

Vulnerability Details

CVEID:CVE-2014-3076

DESCRIPTION:
IBM Business Process Manager 8.5 contains an unprotected JavaServer™ Pages (JSP) file that returns system information to unauthenticated users. An attacker might use this information to aid in further attacks against the system.

CVSS:
CVSS Base Score: 5.0
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/93822 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

    • IBM Business Process Manager Standard
  • IBM Business Process Manager Express
  • IBM Business Process Manager Advanced

Remediation/Fixes

Install IBM Business Process Manager interim fix JR50760 as appropriate for your current IBM Business Process Manager version.

* [_IBM Business Process Manager Standard_](<http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Business+Process+Manager+Standard&release=All&platform=All&function=aparId&apars=JR50760>)
* [_IBM Business Process Manager Express_](<http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Business+Process+Manager+Express&release=All&platform=All&function=aparId&apars=JR50760>)
* [_IBM Business Process Manager Advanced_](<http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Business+Process+Manager+Advanced&release=All&platform=All&function=aparId&apars=JR50760>)

Workarounds and Mitigations

None

EPSS

0.005

Percentile

76.0%

Related for 71E3E7D172741F94122AA1369C26CEDDF9D9EFD69EA9D82DCEB29BB70F53E51E