IBM Security Bulletin: File path traversal vulnerability in IBM Business Process Manager (BPM) and WebSphere Lombardi Edition (WLE) (CVE-2015-1884)
IBM Business Proccess Manager and WebSphere Lombardi Edition are vulnerable to file path traversal. Due to insufficient input parameter validation files can be downloaded by authenticated attackers using specially crafted URLs. CVE(s):...
from IBM Product Security Incident Response Team http://ift.tt/1HblYZj
from IBM Product Security Incident Response Team http://ift.tt/1HblYZj