Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-9693


IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.


Published

2017-03-07T17:59:00.210

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm business_process_manager 7.5.0.0 Yes
Application ibm business_process_manager 7.5.0.0 Yes
Application ibm business_process_manager 7.5.0.0 Yes
Application ibm business_process_manager 7.5.0.0 Yes
Application ibm business_process_manager 7.5.0.1 Yes
Application ibm business_process_manager 7.5.0.1 Yes
Application ibm business_process_manager 7.5.0.1 Yes
Application ibm business_process_manager 7.5.0.1 Yes
Application ibm business_process_manager 7.5.1.0 Yes
Application ibm business_process_manager 7.5.1.0 Yes
Application ibm business_process_manager 7.5.1.0 Yes
Application ibm business_process_manager 7.5.1.0 Yes
Application ibm business_process_manager 7.5.1.1 Yes
Application ibm business_process_manager 7.5.1.1 Yes
Application ibm business_process_manager 7.5.1.1 Yes
Application ibm business_process_manager 7.5.1.1 Yes
Application ibm business_process_manager 7.5.1.2 Yes
Application ibm business_process_manager 7.5.1.2 Yes
Application ibm business_process_manager 7.5.1.2 Yes
Application ibm business_process_manager 7.5.1.2 Yes
Application ibm business_process_manager 8.0.0.0 Yes
Application ibm business_process_manager 8.0.0.0 Yes
Application ibm business_process_manager 8.0.0.0 Yes
Application ibm business_process_manager 8.0.0.0 Yes
Application ibm business_process_manager 8.0.1.0 Yes
Application ibm business_process_manager 8.0.1.0 Yes
Application ibm business_process_manager 8.0.1.0 Yes
Application ibm business_process_manager 8.0.1.0 Yes
Application ibm business_process_manager 8.0.1.1 Yes
Application ibm business_process_manager 8.0.1.1 Yes
Application ibm business_process_manager 8.0.1.1 Yes
Application ibm business_process_manager 8.0.1.1 Yes
Application ibm business_process_manager 8.0.1.2 Yes
Application ibm business_process_manager 8.0.1.2 Yes
Application ibm business_process_manager 8.0.1.2 Yes
Application ibm business_process_manager 8.0.1.2 Yes
Application ibm business_process_manager 8.0.1.3 Yes
Application ibm business_process_manager 8.0.1.3 Yes
Application ibm business_process_manager 8.0.1.3 Yes
Application ibm business_process_manager 8.0.1.3 Yes
Application ibm business_process_manager 8.5.0.0 Yes
Application ibm business_process_manager 8.5.0.0 Yes
Application ibm business_process_manager 8.5.0.0 Yes
Application ibm business_process_manager 8.5.0.0 Yes
Application ibm business_process_manager 8.5.0.1 Yes
Application ibm business_process_manager 8.5.0.1 Yes
Application ibm business_process_manager 8.5.0.1 Yes
Application ibm business_process_manager 8.5.0.1 Yes
Application ibm business_process_manager 8.5.0.2 Yes
Application ibm business_process_manager 8.5.0.2 Yes
Application ibm business_process_manager 8.5.0.2 Yes
Application ibm business_process_manager 8.5.0.2 Yes
Application ibm business_process_manager 8.5.5.0 Yes
Application ibm business_process_manager 8.5.5.0 Yes
Application ibm business_process_manager 8.5.5.0 Yes
Application ibm business_process_manager 8.5.5.0 Yes
Application ibm business_process_manager 8.5.6.0 Yes
Application ibm business_process_manager 8.5.6.0 Yes
Application ibm business_process_manager 8.5.6.0 Yes
Application ibm business_process_manager 8.5.6.0 Yes
Application ibm business_process_manager 8.5.6.2 Yes
Application ibm business_process_manager 8.5.6.2 Yes
Application ibm business_process_manager 8.5.6.2 Yes
Application ibm business_process_manager 8.5.6.2 Yes
Application ibm business_process_manager 8.5.7.0 Yes
Application ibm business_process_manager 8.5.7.0 Yes
Application ibm business_process_manager 8.5.7.0 Yes
Application ibm business_process_manager 8.5.7.0 Yes
Application ibm websphere 7.2 Yes
Application ibm websphere 7.2.0.1 Yes
Application ibm websphere 7.2.0.2 Yes
Application ibm websphere 7.2.0.3 Yes
Application ibm websphere 7.2.0.4 Yes
Application ibm websphere 7.2.0.5 Yes

References