216.73.216.226

CVE-2025-67280

· Published 09/01/2026 16:16 · Modified 09/01/2026 17:15

Labels: CVE-2025-67280 2026-01-09CVE-2025-67280CWE-564[email protected]

Essential information

Published
09/01/2026 16:16
Modified
09/01/2026 17:15
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tim / tim bpm suite cpe:2.3:a:tim:tim_bpm_suite:*:*:*:*:*:*:*:*
tim / tim flow cpe:2.3:a:tim:tim_flow:<9.1.2:*:*:*:*:*:*:*

References