CVE-2014-3087 — Sensitive Information Exposure in IBM Business Process Manager
Severity
4.0MEDIUMNVD
EPSS
0.3%
top 47.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 17
Latest updateMay 17
Description
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9