← voltar
CVE-2025-8532

IDOR in Bimser's eBA Document and Workflow Management System

CVSS 6.4 MEDIUMEPSS 0.1%CWE-285CWE-639
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.4EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
19 set 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing. This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N