CVE-2014-6176: IBM Business Process Manager

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.

Affected products

  • IBM Business Process Manager: version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.1.0 only; version 7.5.1.1 only; version 8.0.0.0 only; version 8.0.1.0 only; …
  • IBM WebSphere Enterprise Service Bus: version 7.0 only
  • IBM WebSphere Process Server: version 7.0 only

Published 2014-12-16. Last modified 2026-06-17.