CVE-2009-5001

IBM FileNet P8 Application Engine 4.0.2.x - Authenticated Access Control Bypass in Workplace Component

Title source: llm
STIX 2.1

Description

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a document's Creator-Owner full control over an annotation object, even if the default instance security has changed, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.

References (2)

Core 2
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PJ35547

Scores

EPSS 0.0103
EPSS Percentile 60.1%

Details

CWE
CWE-264
Status published
Products (1)
ibm/filenet_p8_application_engine 4.0.2 (2 CPE variants)
Published Sep 20, 2010
Tracked Since Feb 18, 2026