CVE-2017-1756: IBM Business Process Manager

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.

Affected products

  • IBM Business Process Manager: version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.1.0 only; version 7.5.1.1 only; version 7.5.1.2 only; version 8.0.0.0 only; …
  • IBM Business Process Manager Enterprise Service Bus: version 8.6.0.0 only
  • IBM WebSphere: version 7.2.0.0 only; version 7.2.0.1 only; version 7.2.0.2 only; version 7.2.0.3 only; version 7.2.0.4 only; version 7.2.0.5 only

Published 2018-03-30. Last modified 2026-06-17.