VYPR
Unrated severityNVD Advisory· Published Oct 7, 2014· Updated Jun 17, 2026

CVE-2014-4802

CVE-2014-4802

Description

The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.0.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.5.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:business_process_manager:8.5.5.0:*:*:*:*:*:*:*
    • (no CPE)range: 8.0 - 8.5.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.