CVE-2010-4806

IBM Web Content Manager 6.1.5 and 7.0.0.1 - Authenticated Access Bypass via Resource Editor Privileges

Title source: llm
STIX 2.1

Description

The authoring tool in IBM Web Content Manager (WCM) 6.1.5, and 7.0.0.1 before CF003, allows remote authenticated users to bypass intended access restrictions on draft creation by leveraging certain resource editor privileges.

References (2)

Core 2
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM26755
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg24029452

Scores

EPSS 0.0103
EPSS Percentile 60.0%

Details

CWE
CWE-264
Status published
Products (2)
ibm/web_content_manager 6.1.5
ibm/web_content_manager 7.0.01 cf002
Published May 26, 2011
Tracked Since Feb 18, 2026