CVE-2017-1766: IBM Business Process Manager

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

Affected products

  • IBM Business Process Manager: version 8.5.5.0 only; version 8.5.6.0 only; version 8.5.6.1 only; version 8.5.6.2 only; version 8.5.7.0 only; version 8.6.0.0 only

Published 2018-03-30. Last modified 2026-06-17.