CVE-2025-67282: Medium severity TIM BPM Suite vulnerability
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67282?
CVE-2025-67282 has a high severity due to its potential for unauthorized access and manipulation of user data.
How do I fix CVE-2025-67282?
To fix CVE-2025-67282, upgrade to a version of TIM BPM Suite or TIM FLOW that is above 9.1.2, which addresses these vulnerabilities.
What types of vulnerabilities are present in CVE-2025-67282?
CVE-2025-67282 includes multiple Authorization Bypass vulnerabilities that can be exploited by low privileged users.
What can a low privileged user access through CVE-2025-67282?
A low privileged user can download password hashes of other users and access their work items due to CVE-2025-67282.
What actions can be manipulated because of CVE-2025-67282?
CVE-2025-67282 allows manipulation of restricted content in workflows and changes to the application's logo.