Vulnerability CVE-2017-1539


Published: 2017-09-26

Description:
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Business process manager 

 References:
http://www.ibm.com/support/docview.wss?uid=swg22007451
http://www.securityfocus.com/bid/100967
https://exchange.xforce.ibmcloud.com/vulnerabilities/130807

Copyright 2024, cxsecurity.com

 

Back to Top