CVE-2008-4581
IBM ENOVIA SmarTeam 5 < 18 SP5 and 19 < SP01 - Authenticated Access Restriction Bypass via Workflow Process View
Title source: llmDescription
The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45943
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1HD71425
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27012567&aid=1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31748
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32105
Scores
EPSS
0.0102
EPSS Percentile
59.9%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/enovia_smarteam
5
Published
Oct 15, 2008
Tracked Since
Feb 18, 2026