CVE-2017-1766
30.03.2018, 16:29
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.0:cf2 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.7.0:cf201606 |
| ibm | business_process_manager | 8.5.7.0:cf201609 |
| ibm | business_process_manager | 8.5.7.0:cf201612 |
| ibm | business_process_manager | 8.5.7.0:cf201703 |
| ibm | business_process_manager | 8.5.7.0:cf201706 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.0:cf2 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.7.0:cf201606 |
| ibm | business_process_manager | 8.5.7.0:cf201609 |
| ibm | business_process_manager | 8.5.7.0:cf201612 |
| ibm | business_process_manager | 8.5.7.0:cf201703 |
| ibm | business_process_manager | 8.5.7.0:cf201706 |
| ibm | business_process_manager | 8.6.0.0 |
| ibm | business_process_manager | 8.6.0.0:cf201712 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.0:cf2 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.7.0:cf201606 |
| ibm | business_process_manager | 8.5.7.0:cf201609 |
| ibm | business_process_manager | 8.5.7.0:cf201612 |
| ibm | business_process_manager | 8.5.7.0:cf201703 |
| ibm | business_process_manager | 8.5.7.0:cf201706 |
𝑥
= Vulnerable software versions