IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.ibm.com/support/docview.wss?uid=ibm10743115 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/153382 | vdb entry vendor advisory |