Access Control Vulnerability in IBM FileNet P8 Application Engine
CVE-2009-5001
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 September 2010
What is CVE-2009-5001?
Inversions in the Workplace component of IBM FileNet P8 Application Engine can lead to inadequate access controls. Specifically, the Creator-Owner of a document may possess full control over associated annotation objects, allowing them to bypass access restrictions set by default security configurations. This weakness could be exploited by remote authenticated users under opportunistic conditions, potentially compromising sensitive information within the system.