CVE-2014-6182: IBM Business Process Manager

Medium severity, CVSS 4.0. EPSS: 2.1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

Affected products

  • IBM Business Process Manager: version 8.0.0.0 only; version 8.0.1.0 only; version 8.0.1.1 only; version 8.0.1.2 only; version 8.0.1.3 only; version 8.5.0.0 only; …

Published 2014-12-17. Last modified 2026-06-17.