IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.
Advisories
Source ID Title
EUVD EUVD EUVD-2011-1062 IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T22:14:27.160Z

Reserved: 2011-02-21T00:00:00

Link: CVE-2011-1046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-02-21T18:00:01.567

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-1046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.