CVE-2025-67281: SQL Injection
Published Jan 9, 2026
·Updated
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content.
Affected Software
3 affected components
TIM BPM Suite<=9.1.2
TIM FLOW<=9.1.2
Tim-solutions Tim Flow<9.1.2
Event History
Jan 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67281?
CVE-2025-67281 is considered a high severity vulnerability due to its potential to allow unauthorized database access.
2
How do I fix CVE-2025-67281?
To fix CVE-2025-67281, upgrade TIM BPM Suite and TIM FLOW to version 9.1.3 or later.
3
Who is affected by CVE-2025-67281?
CVE-2025-67281 affects users of TIM BPM Suite and TIM FLOW versions up to and including 9.1.2.
4
What type of vulnerability is CVE-2025-67281?
CVE-2025-67281 is an SQL injection vulnerability that can be exploited by low privileged and administrative users.
5
Can CVE-2025-67281 lead to data exposure?
Yes, CVE-2025-67281 can lead to unauthorized access and exposure of the database content.