CVE-2009-5001
IBM FileNet P8 Application Engine 4.0.2.x - Authenticated Access Control Bypass in Workplace Component
Title source: llmDescription
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a document's Creator-Owner full control over an annotation object, even if the default instance security has changed, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.
References (2)
Core 2
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PJ35547
Various Sources x_refsource_confirm
http://download2.boulder.ibm.com/sar/CMA/IMA/00y3y/0/readme-4027-P8AE-FP007.htm
Scores
EPSS
0.0103
EPSS Percentile
60.1%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/filenet_p8_application_engine
4.0.2 (2 CPE variants)
Published
Sep 20, 2010
Tracked Since
Feb 18, 2026