CVE-2010-4806

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
26/05/2011
Last modified:
26/05/2011

Description

The authoring tool in IBM Web Content Manager (WCM) 6.1.5, and 7.0.0.1 before CF003, allows remote authenticated users to bypass intended access restrictions on draft creation by leveraging certain resource editor privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:web_content_manager:6.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:web_content_manager:7.0.01:cf002:*:*:*:*:*:*