CVE-2011-1046

IBM FileNet P8 Content Engine 4.0.1-5.0.0 - Unauthenticated Privileged Property Modification

Title source: llm
STIX 2.1

Description

IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65448
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21462438
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46432
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0423
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43347

Scores

EPSS 0.0125
EPSS Percentile 66.2%

Details

CWE
CWE-264
Status published
Products (14)
ibm/filenet_p8_business_process_manager
ibm/filenet_p8_content_engine 4.0.1
ibm/filenet_p8_content_engine 4.0.1.10
ibm/filenet_p8_content_engine 4.0.1.11
ibm/filenet_p8_content_engine 4.0.1.12
ibm/filenet_p8_content_engine 4.0.1.13
ibm/filenet_p8_content_engine 4.5.0
ibm/filenet_p8_content_engine 4.5.0.2
ibm/filenet_p8_content_engine 4.5.1.3
ibm/filenet_p8_content_engine 4.5.1.4
... and 4 more
Published Feb 21, 2011
Tracked Since Feb 18, 2026