CVE-2025-67282 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of o…
Medium CVSS: 5.4

CVE-2025-67282

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.
Vendor
Tim-solutions
Product
Tim Flow
CWE
CWE-288
Yayın Tarihi
2026-01-09 16:16:07
Güncelleme
2026-01-22 21:32:26
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar