MEDIUM · 5.0

CVE-2011-1046

IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access rol...

Vulnerability Description

IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
IbmFilenet P8 Content Engine4.0.1
IbmFilenet P8 Business Process ManagerAll versions
IbmFilenet P8 Content ManagerAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1046?

CVE-2011-1046 is a vulnerability with a CVSS score of 5.0 (MEDIUM). IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access rol...

How severe is CVE-2011-1046?

CVE-2011-1046 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1046?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Filenet P8 Content Engine, Ibm Filenet P8 Business Process Manager, Ibm Filenet P8 Content Manager.