Vulnerability Details CVE-2009-4998
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a security policy to the first document added during a session, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.6%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2009-4998
-
cpe:2.3:a:ibm:filenet_p8_application_engine:3.5.1
-
cpe:2.3:a:ibm:filenet_p8_application_engine:4.0.2