CVE-2014-0908
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail notifications, or modify task assignments via REST API calls.
La implementación User Attribute en IBM Business Process Manager (BPM) 7.5.x hasta 7.5.1.2, 8.0.x hasta 8.0.1.2 y 8.5.x hasta 8.5.0.1 no verifica autorización para acceso de lectura o escritura a valores de atributo, lo que permite a usuarios remotos autenticados obtener información sensible, configurar notificaciones de e-mail o modificar asignaciones de tareas a través de llamadas REST API.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-06 CVE Reserved
- 2014-04-10 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/91870 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1JR49505 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21669330 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 7.5.0.0 Search vendor "Ibm" for product "Business Process Manager" and version "7.5.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 7.5.0.1 Search vendor "Ibm" for product "Business Process Manager" and version "7.5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 7.5.1.0 Search vendor "Ibm" for product "Business Process Manager" and version "7.5.1.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 7.5.1.1 Search vendor "Ibm" for product "Business Process Manager" and version "7.5.1.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 7.5.1.2 Search vendor "Ibm" for product "Business Process Manager" and version "7.5.1.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 8.0.0.0 Search vendor "Ibm" for product "Business Process Manager" and version "8.0.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 8.0.1.0 Search vendor "Ibm" for product "Business Process Manager" and version "8.0.1.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 8.0.1.1 Search vendor "Ibm" for product "Business Process Manager" and version "8.0.1.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 8.0.1.2 Search vendor "Ibm" for product "Business Process Manager" and version "8.0.1.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 8.5.0.0 Search vendor "Ibm" for product "Business Process Manager" and version "8.5.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Business Process Manager Search vendor "Ibm" for product "Business Process Manager" | 8.5.0.1 Search vendor "Ibm" for product "Business Process Manager" and version "8.5.0.1" | - |
Affected
|