CVE-2025-67282

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tim-solutions:tim_flow:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) En TIM BPM Suite/ TIM FLOW a través de 9.1.2 existen múltiples vulnerabilidades de omisión de autorización que permiten a un usuario con pocos privilegios descargar hashes de contraseñas de otros usuarios, acceder a elementos de trabajo de otros usuarios, modificar contenido restringido en flujos de trabajo, modificar el logotipo de las aplicaciones y manipular el perfil de otros usuarios.

22 Jan 2026, 21:32

Type Values Removed Values Added
First Time Tim-solutions
Tim-solutions tim Flow
References () https://tim-doc.atlassian.net/wiki/spaces/eng/pages/230981636/Release+Notes - () https://tim-doc.atlassian.net/wiki/spaces/eng/pages/230981636/Release+Notes - Release Notes
References () https://www.y-security.de/news-en/tim-bpm-suite-tim-flow-multiple-vulnerabilities/ - () https://www.y-security.de/news-en/tim-bpm-suite-tim-flow-multiple-vulnerabilities/ - Third Party Advisory
CPE cpe:2.3:a:tim-solutions:tim_flow:*:*:*:*:*:*:*:*

09 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 16:16

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67282

Mitre link : CVE-2025-67282

CVE.ORG link : CVE-2025-67282


JSON object : View

Products Affected

tim-solutions

  • tim_flow
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel