CVE-2025-67279: Medium severity TIM Solution GmbH TIM BPM Suite & TIM FLOW vulnerability
Published Jan 9, 2026
·Updated
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format
Affected Software
2 affected components
TIM Solution GmbH TIM BPM Suite & TIM FLOW<9.1.2
Tim-solutions Tim Flow<9.1.2
Event History
Jan 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67279?
CVE-2025-67279 has been rated as a high severity vulnerability due to its potential for privilege escalation.
2
How can I fix CVE-2025-67279?
To mitigate CVE-2025-67279, upgrade TIM BPM Suite & TIM FLOW to version 9.1.2 or higher where the vulnerability has been addressed.
3
Who is affected by CVE-2025-67279?
CVE-2025-67279 affects users of TIM Solution GmbH TIM BPM Suite & TIM FLOW versions prior to 9.1.2.
4
What type of vulnerability is CVE-2025-67279?
CVE-2025-67279 is a privilege escalation vulnerability due to insecure password hashing using MD5.
5
Can CVE-2025-67279 be exploited remotely?
Yes, CVE-2025-67279 can be exploited remotely by attackers to elevate their privileges within the application.