IBM WebSphere Process Server access Restriction Bypass Vulnerability (CVE-2015-7454)
IBM WebSphere Process Server access Restriction Bypass Vulnerability (CVE-2015-7454)
Release date:
Updated on:
Affected Systems:
IBM WebSphere Process Server 6.1.2.0 - 7.0.0.5
IBM Business Process Manager Advanced 8.5.6.x - 8.5.6.2
IBM Business Process Manager Advanced 8.5.5.x - 8.5.5.0
IBM Business Process Manager Advanced 8.5.0.x - 8.5.0.2
IBM Business Process Manager Advanced 8.0.x - 8.0.1.3
IBM Business Process Manager Advanced 7.5.x - 7.5.1.2
Description:
CVE (CAN) ID: CVE-2015-7454
IBM WebSphere Process Server is a business Process automation engine.
In some IBM WebSphere Process Server versions, a security vulnerability exists in Business Space. Remote attackers can exploit this vulnerability to bypass access restrictions and create arbitrary pages or spaces.
<* Source: IBM (ncsupp@ca.ibm.com)
*>
Suggestion:
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg1JR54678
Http://www-01.ibm.com/support/docview.wss? Uid = swg21972005
This article permanently updates the link address: