CVE-2014-4758
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0020 (0.2%)
Percentile: 42.0%
EPSS: 2026-05-06
Affects
ibm:business_process_manageribm:websphere_application_serverTechnical description
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
Published: 9/4/2014, 10:55:07 AM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://secunia.com/advisories/60851
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR50215
- http://www-01.ibm.com/support/docview.wss?uid=swg21680795
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94485
- http://secunia.com/advisories/60851
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR50215
- http://www-01.ibm.com/support/docview.wss?uid=swg21680795
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94485