CVE-2015-0110: IBM Business Process Manager
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
Affected products
- IBM Business Process Manager: version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.1.0 only; version 7.5.1.1 only; version 7.5.1.2 only; version 8.0.0.0 only; …
- IBM WebSphere Application Server: version 7.2.0.0 only; version 7.2.0.1 only; version 7.2.0.2 only; version 7.2.0.3 only; version 7.2.0.4 only; version 7.2.0.5 only
Published 2017-09-15. Last modified 2026-06-17.