CVE-2017-1539
CVE-2017-1539
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Sep 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
Affected products
IBM · Business Process Manager AdvancedWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →