The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.
References
Configurations
History
21 Nov 2024, 00:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/32105 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg27012567&aid=1 - Vendor Advisory | |
References | () http://www-1.ibm.com/support/docview.wss?uid=swg1HD71425 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/31748 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/45943 - |
Information
Published : 2008-10-15 20:08
Updated : 2025-04-09 00:30
NVD link : CVE-2008-4581
Mitre link : CVE-2008-4581
CVE.ORG link : CVE-2008-4581
JSON object : View
Products Affected
ibm
- enovia_smarteam
CWE
CWE-264
Permissions, Privileges, and Access Controls