In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-288 | |
| Metrics |
cvssV3_1
|
Fri, 09 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-09T16:10:18.983Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67282
Updated: 2026-01-09T16:10:14.084Z
Status : Received
Published: 2026-01-09T16:16:07.623
Modified: 2026-01-09T16:16:07.623
Link: CVE-2025-67282
No data.
OpenCVE Enrichment
No data.