The Outlook Extension in IBM Content Collector 4.0.0.x before 4.0.0.0-ICC-OE-IF004 allows local users to bypass the intended Reviewer privilege requirement and read e-mail messages from an arbitrary mailbox by invoking the Search function.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/60619 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/94456 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21679144 | patch vendor advisory |