Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-1046


IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.


Published

2011-02-21T18:00:01.567

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm filenet_p8_content_engine 4.0.1 Yes
Application ibm filenet_p8_content_engine 4.0.1.10 Yes
Application ibm filenet_p8_content_engine 4.0.1.11 Yes
Application ibm filenet_p8_content_engine 4.0.1.12 Yes
Application ibm filenet_p8_content_engine 4.0.1.13 Yes
Application ibm filenet_p8_content_engine 4.5.0 Yes
Application ibm filenet_p8_content_engine 4.5.0.2 Yes
Application ibm filenet_p8_content_engine 4.5.1.3 Yes
Application ibm filenet_p8_content_engine 4.5.1.4 Yes
Application ibm filenet_p8_content_engine 4.5.1.5 Yes
Application ibm filenet_p8_content_engine 4.5.1.6 Yes
Application ibm filenet_p8_content_engine 5.0.0 Yes
Application ibm filenet_p8_business_process_manager * Yes
Application ibm filenet_p8_content_manager * Yes

References