CVE-2014-3087 PUBLISHED CVSS 4 MEDIUM

callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS 0.29% · 52.3th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.29%
52.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
ibmbusiness_process_manager7.5.0.0, 7.5.0.1, 7.5.1.0
ibmwebsphere_application_server7.2

Timeline

References

Open in Interactive Console →