CVE-2010-2896
Last modified
CVE-2010-2896 is a vulnerability of currently unknown severity. IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Filenet Content Manager | 4.0.0 |
| Ibm | Filenet Content Manager | 4.0.1 |
| Ibm | Filenet Content Manager | 4.5.0 |
| Ibm | Filenet Content Manager | 4.5.1 |
References
- http://secunia.com/advisories/40614Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21441225Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1847Vendor Advisory
- http://secunia.com/advisories/40614Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21441225Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1847Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2896?
How severe is CVE-2010-2896?
How do I fix CVE-2010-2896?
Are you affected by CVE-2010-2896?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
