Vulnerability Details CVE-2015-7454
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.0%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2015-7454
-
cpe:2.3:a:ibm:business_process_manager:7.5.0.0
-
cpe:2.3:a:ibm:business_process_manager:7.5.0.1
-
cpe:2.3:a:ibm:business_process_manager:7.5.1.0
-
cpe:2.3:a:ibm:business_process_manager:7.5.1.1
-
cpe:2.3:a:ibm:business_process_manager:7.5.1.2
-
cpe:2.3:a:ibm:business_process_manager:8.0.0.0
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.0
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.1
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.2
-
cpe:2.3:a:ibm:business_process_manager:8.0.1.3
-
cpe:2.3:a:ibm:business_process_manager:8.5.0.0
-
cpe:2.3:a:ibm:business_process_manager:8.5.0.1
-
cpe:2.3:a:ibm:business_process_manager:8.5.0.2
-
cpe:2.3:a:ibm:business_process_manager:8.5.5.0
-
cpe:2.3:a:ibm:business_process_manager:8.5.6.0
-
cpe:2.3:a:ibm:business_process_manager:8.5.6.1
-
cpe:2.3:a:ibm:business_process_manager:8.5.6.2
-
cpe:2.3:a:ibm:websphere_process_server:6.1.2
-
cpe:2.3:a:ibm:websphere_process_server:6.1.2.1
-
cpe:2.3:a:ibm:websphere_process_server:6.1.2.2
-
cpe:2.3:a:ibm:websphere_process_server:6.1.2.3
-
cpe:2.3:a:ibm:websphere_process_server:6.2
-
cpe:2.3:a:ibm:websphere_process_server:6.2.0.1
-
cpe:2.3:a:ibm:websphere_process_server:6.2.0.2
-
cpe:2.3:a:ibm:websphere_process_server:6.2.0.3
-
cpe:2.3:a:ibm:websphere_process_server:7.0
-
cpe:2.3:a:ibm:websphere_process_server:7.0.0.1
-
cpe:2.3:a:ibm:websphere_process_server:7.0.0.2
-
cpe:2.3:a:ibm:websphere_process_server:7.0.0.3
-
cpe:2.3:a:ibm:websphere_process_server:7.0.0.4
-
cpe:2.3:a:ibm:websphere_process_server:7.0.0.5