CVE-2015-1905
published 2015-07-21CVE-2015-1905: The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6…
PriorityP422medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.49%
71.5th percentile
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5220 OOME from EAP 6 http management console
bugzilla·2015-08-21·CVSS 5.0
CVE-2015-5220 [MEDIUM] CVE-2015-5220 OOME from EAP 6 http management console
CVE-2015-5220 OOME from EAP 6 http management console
no sanity checks and unbounded header sizes/counts leads to OOME from EAP 6 http management console
Discussion:
Acknowledgement:
This issue was discovered by Aaron Ogburn of Red Hat GSS Middleware Team
---
This issue has been addressed in the following products:
JBEAP 6.4.z for RHEL 6
Via RHSA-2015:1907 https://rhn.redhat.com/errata/RHSA-2015-1907.html
---
This issue has been addressed in the following products:
JBEAP 6.4.z for RHEL 6
Via RHSA-2015:1905 https://rhn.redhat.com/errata/RHSA-2015-1905.html
---
This issue has been addressed in the following products:
JBEAP 6.4.z for RHEL 5
Via RHSA-2015:1904 https://rhn.redhat.com/errata/RHSA-2015-1904.html
---
This issue has been addressed in the following products:
JBEAP
Bugzilla
CVE-2015-5178 JBoss AS/WildFly: missing X-Frame-Options header leading to clickjacking
bugzilla·2015-08-05·CVSS 4.3
CVE-2015-5178 [MEDIUM] CVE-2015-5178 JBoss AS/WildFly: missing X-Frame-Options header leading to clickjacking
CVE-2015-5178 JBoss AS/WildFly: missing X-Frame-Options header leading to clickjacking
It was reported that the EAP console is vulnerable to clickjacking attacks because it does not set the X-Frame-Options HTTP header. An attacker could use this flaw to embedded the EAP console in a web page using a frame or iframe, and then trick a user into performing arbitrary actions in the console.
Discussion:
This issue has been addressed in the following products:
JBEAP 6.4.z for RHEL 6
Via RHSA-2015:1907 https://rhn.redhat.com/errata/RHSA-2015-1907.html
---
This issue has been addressed in the following products:
JBEAP 6.4.z for RHEL 6
Via RHSA-2015:1905 https://rhn.redhat.com/errata/RHSA-2015-1905.html
---
This issue has been addressed in the following products:
JBEAP 6.4.z for RHEL 5
http://www-01.ibm.com/support/docview.wss?uid=swg1JR52772http://www-01.ibm.com/support/docview.wss?uid=swg21700717http://www.securityfocus.com/bid/75977http://www.securitytracker.com/id/1033002http://www-01.ibm.com/support/docview.wss?uid=swg1JR52772http://www-01.ibm.com/support/docview.wss?uid=swg21700717http://www.securityfocus.com/bid/75977http://www.securitytracker.com/id/1033002
2015-07-21
Published