cbcvebase.
CVE-2017-1766
published 2018-03-30

CVE-2017-1766: Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

medium4.3CVSS 3.0
AVNACLPRLUINSUCNILAN
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

Affected

8 ranges
VendorProductVersion rangeFixed in
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager