CVE-2010-4806
IBM Web Content Manager 6.1.5 and 7.0.0.1 - Authenticated Access Bypass via Resource Editor Privileges
Title source: llmDescription
The authoring tool in IBM Web Content Manager (WCM) 6.1.5, and 7.0.0.1 before CF003, allows remote authenticated users to bypass intended access restrictions on draft creation by leveraging certain resource editor privileges.
References (2)
Core 2
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM26755
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg24029452
Scores
EPSS
0.0103
EPSS Percentile
60.0%
Details
CWE
CWE-264
Status
published
Products (2)
ibm/web_content_manager
6.1.5
ibm/web_content_manager
7.0.01 cf002
Published
May 26, 2011
Tracked Since
Feb 18, 2026