System information is provided on an unprotected diagnostic page.
CVEID:CVE-2014-3076
DESCRIPTION:
IBM Business Process Manager 8.5 contains an unprotected JavaServer™ Pages (JSP) file that returns system information to unauthenticated users. An attacker might use this information to aid in further attacks against the system.
CVSS:
CVSS Base Score: 5.0
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/93822 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Install IBM Business Process Manager interim fix JR50760 as appropriate for your current IBM Business Process Manager version.
* [_IBM Business Process Manager Standard_](<http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Business+Process+Manager+Standard&release=All&platform=All&function=aparId&apars=JR50760>)
* [_IBM Business Process Manager Express_](<http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Business+Process+Manager+Express&release=All&platform=All&function=aparId&apars=JR50760>)
* [_IBM Business Process Manager Advanced_](<http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Business+Process+Manager+Advanced&release=All&platform=All&function=aparId&apars=JR50760>)
None