Description
IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.
Published: 2011-02-21
Score: 5.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2011-1062 IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.
History

No history.

Subscriptions

Ibm Filenet P8 Business Process Manager Filenet P8 Content Engine Filenet P8 Content Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T22:14:27.160Z

Reserved: 2011-02-21T00:00:00.000Z

Link: CVE-2011-1046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-02-21T18:00:01.567

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-1046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses