In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple...
Moderate severity
Unreviewed
Published
Jan 9, 2026
to the GitHub Advisory Database
•
Updated Jan 9, 2026
Description
Published by the National Vulnerability Database
Jan 9, 2026
Published to the GitHub Advisory Database
Jan 9, 2026
Last updated
Jan 9, 2026
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.
References