CVE-2006-7241

IBM FileNet P8 Application Engine 3.5.1 - Authenticated ACL Bypass in Image Viewer

Title source: llm
STIX 2.1

Description

The Image Viewer component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-002 removes a user from an ACL when the user is denied all permissions for an annotation, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.

References (1)

Core 1
Core References

Scores

EPSS 0.0106
EPSS Percentile 61.0%

Details

CWE
CWE-264
Status published
Products (1)
ibm/filenet_p8_application_engine 3.5.1 (2 CPE variants)
Published Sep 20, 2010
Tracked Since Feb 18, 2026