Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Business Process Manager 目录遍历漏洞
Vulnerability Description
IBM Business Process Manager(BPM)是美国IBM公司的一套综合的业务流程管理平台。该平台为业务的流程建模、组装、监控和部署提供了一系列的相关工具。 IBM BPM 8.0.x版本至8.0.1.3版本和8.5.x版本至8.5.5版本的Process Center中的导出函数存在目录遍历漏洞。远程攻击者可借助URL中的目录遍历字符‘..’利用该漏洞读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A