CVE-2010-2518
Last modified
CVE-2010-2518 is a vulnerability of currently unknown severity. Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before FP1, as used in IBM FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), allows remote attackers to gain privileges via unknown vectors. NOTE: some of these details are obtained from third party information.. EPSS estimates a 1.61% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before FP1, as used in IBM FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), allows remote attackers to gain privileges via unknown vectors. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | P8 Content Engine | 4.5.1 |
| Ibm | P8 Content Engine | 4.5.1.1 |
| Ibm | P8 Content Engine | 4.5.1.2 |
| Ibm | P8 Content Search Engine | 4.5.0 |
| Ibm | P8 Content Search Engine | 4.5.0.1 |
| Ibm | P8 Content Search Engine | 4.5.0.2 |
| Ibm | P8 Content Search Engine | 4.5.1 |
References
- http://secunia.com/advisories/40413Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21438487Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1616Vendor Advisory
- http://secunia.com/advisories/40413Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21438487Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1616Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2518?
How severe is CVE-2010-2518?
How do I fix CVE-2010-2518?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-2512SQL injection vulnerability in customprofile.php in 2daybiz …
- CVE-2010-2513SQL injection vulnerability in the JE Ajax Event Calendar (c…
- CVE-2010-2514Cross-site scripting (XSS) vulnerability in the JFaq (com_jf…
- CVE-2010-2515Multiple SQL injection vulnerabilities in index.php in the J…
- CVE-2010-2516Multiple SQL injection vulnerabilities in 2daybiz Multi Leve…
- CVE-2010-2517Multiple unspecified vulnerabilities in IBM Rational ClearQu…
- CVE-2010-2519Heap-based buffer overflow in the Mac_Read_POST_Resource fun…
- CVE-2010-2520Heap-based buffer overflow in the Ins_IUP function in truety…
- CVE-2010-2521Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR im…
- CVE-2010-2522The mipv6 daemon in UMIP 0.4 does not verify that netlink me…
- CVE-2010-2523Multiple buffer overflows in ha.c in the mipv6 daemon in UMI…
- CVE-2010-2524The DNS resolution functionality in the CIFS implementation …7.8
Are you affected by CVE-2010-2518?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
