Skip to main content

Vendor/product archive

tim-solutions / tim_flow CVEs

Beta · best-effort

5 CVEs tagged to tim-solutions / tim_flow0 Critical, 0 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-67282

Published Jan 9, 2026

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access w…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67281

Published Jan 9, 2026

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67280

Published Jan 9, 2026

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users an…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67279

Published Jan 9, 2026

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67278

Published Jan 9, 2026

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1