Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.