1. IBM Business Process Manager 7.x
Danger: Low
Availability Corrections: Yes
Number of vulnerabilities: 1
CVSSv2 Rating: (AV: N / AC: M / Au: N / C: P / I: N / A: N / E: U / RL: O / RC: C) =
CVE ID: CVE-2014-3087
Vector operation: LAN (Local area network)
Impact: Disclosure of sensitive data
Affected Products: IBM Business Process Manager 7.x
Affected versions:
IBM Business Process Manager 7.5, 7.5.0.1, 7.5.1, 7.5.1.1, 7.5.1.2
Description:
Vulnerabilities allow a remote user to gain access to sensitive data.
The vulnerability is caused due to insufficient processing of the input XML data associated with the service callService.do. This can be exploited via a specially crafted XML document to gain access to confidential data.
2. IBM Business Process Manager 8.x
Danger: Low
Availability Corrections: Yes
Number of vulnerabilities: 1
CVSSv2 Rating: (AV: N / AC: M / Au: N / C: P / I: N / A: N / E: U / RL: O / RC: C) = Base: 4.3 / Temporal: 3.2
CVE ID: CVE-2014-3087
Vector operation: LAN (Local area network)
Impact: Disclosure of sensitive data
Affected Products: IBM Business Process Manager 8.x
Affected versions: Dolibarr CMS 3.5.3, possibly earlier versions
Description:
Vulnerabilities allow a remote user to gain access to certain confidential information.
The vulnerability is caused due to insufficient processing of the input XML data associated with the service callService.do. This can be exploited via a specially crafted XML document to gain access to confidential data.
Solution: Install the latest version of APAR JR50616 from the manufacturer.
Manufacturer: http://www.ibm.com/
Link: http://www.ibm.com/support/docview.wss?uid=swg21679726