CVE-2025-67278 | TIM BPM Suite/FLOW up to 9.1.1 HTTP Request privileges assignment
A vulnerability has been found in TIM BPM Suite and FLOW up to 9.1.1 and classified as critical. This affects an unknown part of the component HTTP Request Handler. Performing a manipulation results in incorrect privilege assignment.
This vulnerability is reported as CVE-2025-67278. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.