IBM Support

JR61681: SECURITY APAR - CVE-2015-7450 AFFECTS IBM PROCESS DESIGNER

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • A vulnerability in Apache commons affects IBM Process Designer
    for IBM Business Automation Workflow.
    
    CVEID:   CVE-2015-7450
    DESCRIPTION:   Serialized-object interfaces in certain IBM
    analytics, business solutions, cognitive, IT infrastructure, and
    mobile and social products allow remote attackers to execute
    arbitrary commands via a crafted serialized Java object, related
    to the InvokerTransformer class in the Apache Commons
    Collections library.
    CVSS Base score: 9.8
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
    

Local fix

Problem summary

  • No additional information is available.
    
    PRODUCTS AFFECTED
    IBM Business Automation Workflow
    IBM Business Process Manager (BPM) Advanced
    IBM BPM Standard
    IBM BPM Express
    

Problem conclusion

  • A fix that resolves CVE-2015-7450 in Process Designer is
    available for the latest fix pack for IBM BPM V8.0.1.3, V8.5.7
    V8.6, Business Automation Workflow V18.0.0.1, V19.0.0.1,
    V19.0.0.2, V19.0.0.3, and it is planned for inclusion in future
    releases of Business Automation Workflow.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR61681

  • Reported component name

    BUS AUTO WORKFL

  • Reported component ID

    5737H4100

  • Reported release

    I00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-11-20

  • Closed date

    2019-12-23

  • Last modified date

    2019-12-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BUS AUTO WORKFL

  • Fixed component ID

    5737H4100

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS8JB4","label":"IBM Business Automation Workflow"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18.0.0.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
22 June 2020