First published: Wed Jul 28 2010(Updated: )
IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FileNet Content Manager | =4.5.0 | |
IBM FileNet Content Manager | =4.0.1 | |
IBM FileNet Content Manager | =4.0.0 | |
IBM FileNet Content Manager | =4.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2896 is classified as a medium severity vulnerability due to its capability of allowing permission bypass.
CVE-2010-2896 affects IBM FileNet Content Manager versions 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4.
To fix CVE-2010-2896, you should upgrade to the latest version of IBM FileNet Content Manager that includes the security patch.
CVE-2010-2896 is a security vulnerability that relates to improper permission management during upgrades.
Yes, CVE-2010-2896 can potentially be exploited remotely if the folder permissions are not properly managed.