cve/2025/CVE-2025-8532.md

20 lines
1.2 KiB
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2025-8532](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8532)
![](https://img.shields.io/static/v1?label=Product&message=eBA%20Document%20and%20Workflow%20Management%20System&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=6.7.164%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE%20-%20862%20-%20Missing%20Authorization&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-285%20%E2%80%93%20Improper%20Authorization&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-639%20Authorization%20Bypass%20Through%20User-Controlled%20Key&color=brightgreen)
### Description
Authorization Bypass Through User-Controlled Key, CWE - 862 - Missing Authorization, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Exploitation of Trusted Identifiers, Exploitation of Authorization, Variable Manipulation.This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds