IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.
The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.
During installation, installed file permissions are set to allow anyone to modify those files.