Loading HuntDB...

GHSA-vp3c-hw54-76fg

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.

Related CVEs

Key Information

GHSA ID
GHSA-vp3c-hw54-76fg
Published
May 17, 2022 2:47 AM
Last Modified
May 17, 2022 2:47 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.