Security Advisory

CVE-2015-1961

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2015-07-13 16:00:00
Last updated 2024-08-06 05:02:41
Assigner ibm
State PUBLISHED

Description

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.