Required CVE Record Information
Description
An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- exchange.xforce.ibmcloud.com: ibm-websphere-cve20144759-info-disc(94486) vdb-entryx_transferred
- www-01.ibm.com: JR50871 vendor-advisoryx_transferred
- http://www-01.ibm.com/support/docview.wss?uid=swg21680809 x_transferred