tim-solutions records
5 published records for vendor tim-solutions.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-266 Incorrect Privilege Assignment2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-564 SQL Injection: Hibernate1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2025-67278No exploit | An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP reqtim-solutions · tim flow · CWE-266 | Medium6.5 | — | 0.3% | Jan 9, 2026 |
21Monitor | CVE-2025-67279No exploit | An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application sttim-solutions · tim flow · CWE-266 | Medium5.3 | — | 0.4% | Jan 9, 2026 |
21Monitor | CVE-2025-67280No exploit | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged usertim-solutions · tim flow · CWE-564 | Medium5.4 | — | 0.2% | Jan 9, 2026 |
21Monitor | CVE-2025-67282No exploit | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download tim-solutions · tim flow · CWE-288 | Medium5.4 | — | 0.2% | Jan 9, 2026 |
21Monitor | CVE-2025-67281No exploit | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user tim-solutions · tim flow · CWE-89 | Medium5.4 | — | 0.2% | Jan 9, 2026 |
- CVE-2025-6727826Monitor
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP req
MediumCVSS 6.5No exploitEPSS 0%tim-solutions · tim flowJan 9, 2026
- CVE-2025-6727921Monitor
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application st
MediumCVSS 5.3No exploitEPSS 0%tim-solutions · tim flowJan 9, 2026
- CVE-2025-6728021Monitor
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user
MediumCVSS 5.4No exploitEPSS 0%tim-solutions · tim flowJan 9, 2026
- CVE-2025-6728221Monitor
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download
MediumCVSS 5.4No exploitEPSS 0%tim-solutions · tim flowJan 9, 2026
- CVE-2025-6728121Monitor
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user
MediumCVSS 5.4No exploitEPSS 0%tim-solutions · tim flowJan 9, 2026