CVE-2014-4759
IBM Business Process Manager 8.5.x-8.5.5 - Authenticated Information Disclosure via Content Management Ajax Service
Title source: llmDescription
An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/94486
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR50871
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21680809
Scores
EPSS
0.0108
EPSS Percentile
61.7%
Details
CWE
CWE-264
Status
published
Products (3)
ibm/business_process_manager
8.5.0.0
ibm/business_process_manager
8.5.0.1
ibm/business_process_manager
8.5.5.0
Published
Sep 04, 2014
Tracked Since
Feb 18, 2026