The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a document's Creator-Owner full control over an annotation object, even if the default instance security has changed, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2010-09-20T21:00:00Z
Updated: 2024-09-16T20:07:19.584Z
Reserved: 2010-09-20T00:00:00Z
Link: CVE-2009-5001
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-09-20T22:00:03.407
Modified: 2024-11-21T01:10:57.800
Link: CVE-2009-5001
Redhat
No data.