CVE-2014-4758IBM Business Process Manager vulnerability

CWE-2644 documents4 sources
Severity
4.0MEDIUMNVD
EPSS
0.2%
top 57.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateMay 17

Description

IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2vqr-3j4p-r5j5: IBM Business Process Manager (BPM) 72022-05-17
CVEList
CVE-2014-4758: IBM Business Process Manager (BPM) 72014-09-04
CVE-2014-4758 — IBM vulnerability | cvebase