CVE-2025-67282: Medium severity TIM BPM Suite vulnerability

Published Jan 9, 2026
·
Updated

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

Affected Software

3 affected components
TIM BPM Suite<=9.1.2
TIM FLOW<=9.1.2
Tim-solutions Tim Flow<9.1.2

Event History

Jan 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-67282?

CVE-2025-67282 has a high severity due to its potential for unauthorized access and manipulation of user data.

2

How do I fix CVE-2025-67282?

To fix CVE-2025-67282, upgrade to a version of TIM BPM Suite or TIM FLOW that is above 9.1.2, which addresses these vulnerabilities.

3

What types of vulnerabilities are present in CVE-2025-67282?

CVE-2025-67282 includes multiple Authorization Bypass vulnerabilities that can be exploited by low privileged users.

4

What can a low privileged user access through CVE-2025-67282?

A low privileged user can download password hashes of other users and access their work items due to CVE-2025-67282.

5

What actions can be manipulated because of CVE-2025-67282?

CVE-2025-67282 allows manipulation of restricted content in workflows and changes to the application's logo.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203