IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6
could allow an authenticated user to delete another users comments due to improper ownership management.
The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.