Executive brief
A security vulnerability exists in the Bimser eBA Document and Workflow Management System, a platform used by organizations to manage digital documents and business processes. An attacker with low-level access to the system could bypass security checks to view or modify documents they are not authorized to see. This could lead to unauthorized data access or the manipulation of sensitive business records.
Technical details
The Bimser eBA Document and Workflow Management System (versions 6.7.164 through 6.7.165) contains an improper authorization vulnerability (CWE-285) and an authorization bypass through a user-controlled key (CWE-639). The flaw allows for 'forceful browsing,' where an attacker can access restricted pages or data by guessing or manipulating identifiers (such as document IDs or keys) in the application's URL or parameters. While the attack vector is classified as local with high complexity, a successful exploit allows a low-privileged user to achieve unauthorized data modification and limited information disclosure. The issue is addressed in version 6.7.166.
Affected products
- Bimser Solution Software Trade Inc. eBA Document and Workflow Management System from 6.7.164 before 6.7.166
Timeline
- 2025-09-19: disclosed
- 2025-09-19: advisory