CVE-2014-3087Sensitive Information Exposure in IBM Business Process Manager

Severity
4.0MEDIUMNVD
EPSS
0.3%
top 47.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 17

Description

callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cpvq-xh34-28q8: callService2022-05-17
CVEList
CVE-2014-3087: callService2014-08-17
CVE-2014-3087 — Sensitive Information Exposure in IBM | cvebase