CVE-2015-7441IBM Business Process Manager vulnerability

CWE-174 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
0.2%
top 51.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 1
Latest updateMay 17

Description

Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-rjpq-9c64-924q: Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 72022-05-17
CVEList
CVE-2015-7441: Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 72016-01-01
OSV
nbd vulnerabilities2015-07-22
CVE-2015-7441 — IBM vulnerability | cvebase