CVE-2006-7242

IBM FileNet P8 Application Engine 3.5.1 - Authenticated Access Control Bypass in Workplace Component

Title source: llm
STIX 2.1

Description

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-001 does not ensure that the AE Administrator role is present for Site Preferences modifications, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

References (1)

Core 1
Core References

Scores

EPSS 0.0106
EPSS Percentile 61.0%

Details

CWE
CWE-264
Status published
Products (1)
ibm/filenet_p8_application_engine 3.5.1
Published Sep 20, 2010
Tracked Since Feb 18, 2026