PT-2011-1752 · Ibm · Ibm Web Content Manager
Published
2011-05-26
·
Updated
2011-05-26
·
CVE-2010-4806
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Web Content Manager versions 6.1.5, 7.0.0.1 before CF003
Description
The issue allows remote authenticated users to bypass intended access restrictions on draft creation by leveraging certain resource editor privileges.
Recommendations
For IBM Web Content Manager version 6.1.5, apply a fix to restrict resource editor privileges.
For IBM Web Content Manager version 7.0.0.1, apply Cumulative Fix CF003 or later to address the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Web Content Manager