Service inputs can be passed into callService.do as URL parameters in an XML format. Because of insufficient input validation, XML injection attacks are possible.
CVE ID:CVE-2014-3087
DESCRIPTION:
IBM WebSphere Lombardi Edition and IBM Business Process Manager might allow a remote attacker to obtain sensitive information, which is caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially crafted XML data, an attacker might exploit this vulnerability to obtain sensitive information.
**CVSS: *CVSS Base Score: 4.0
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/94112 for the current score
CVSS Environmental Score: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)
* IBM Business Process Manager Express Versions 7.5.x, 8.0.x, 8.5.0, and 8.5.5
* IBM Business Process Manager Standard Versions 7.5.x, 8.0.x, 8.5.0, and 8.5.5
* IBM Business Process Manager Advanced Versions 7.5.x, 8.0.x, 8.5.0, and 8.5.5
* IBM WebSphere Lombardi Edition Version 7.2
Install interim fix JR50616 as appropriate for your current IBM Business Process Manager or WebSphere Lombardi Edition version.
None