Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
| Software | From | Fixed in |
|---|---|---|
| ibm / business_process_manager | 8.5.5.0 | 8.5.5.0.x |
| ibm / business_process_manager | 8.5.6.2 | 8.5.6.2.x |
| ibm / business_process_manager | 8.5.6.1 | 8.5.6.1.x |
| ibm / business_process_manager | 8.5.7.0 | 8.5.7.0.x |
| ibm / business_process_manager | 8.5.6.0 | 8.5.6.0.x |
| ibm / business_process_manager | 8.5.7.0-cf201706 | 8.5.7.0-cf201706.x |
| ibm / business_process_manager | 8.5.7.0-cf201703 | 8.5.7.0-cf201703.x |
| ibm / business_process_manager | 8.5.7.0-cf201612 | 8.5.7.0-cf201612.x |
| ibm / business_process_manager | 8.5.7.0-cf201609 | 8.5.7.0-cf201609.x |
| ibm / business_process_manager | 8.5.7.0-cf201606 | 8.5.7.0-cf201606.x |
| ibm / business_process_manager | 8.5.6.0-cf2 | 8.5.6.0-cf2.x |
| ibm / business_process_manager | 8.6.0.0 | 8.6.0.0.x |
| ibm / business_process_manager | 8.6.0.0-cf201712 | 8.6.0.0-cf201712.x |