Vulnerabilities > CVE-2015-7441 - Code vulnerability in IBM Business Process Manager and Websphere Process Server
Attack vector
NETWORK Attack complexity
HIGH Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://www.securitytracker.com/id/1034531
- http://www.securitytracker.com/id/1034531
- http://www.securitytracker.com/id/1034532
- http://www.securitytracker.com/id/1034532
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR54760
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR54760
- https://www-01.ibm.com/support/docview.wss?uid=swg21971968
- https://www-01.ibm.com/support/docview.wss?uid=swg21971968