CVE-2015-7454: IBM Business Process Manager
Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.
Affected products
- IBM Business Process Manager: version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.1.0 only; version 7.5.1.1 only; version 7.5.1.2 only; version 8.0.0.0 only; …
- IBM WebSphere Process Server: version 6.1.2 only; version 6.1.2.1 only; version 6.1.2.2 only; version 6.1.2.3 only; version 6.2 only; version 6.2.0.1 only; …
Published 2016-03-21. Last modified 2026-06-17.