CVE-2008-4581

IBM ENOVIA SmarTeam 5 < 18 SP5 and 19 < SP01 - Authenticated Access Restriction Bypass via Workflow Process View

Title source: llm
STIX 2.1

Description

The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45943
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1HD71425
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31748
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32105

Scores

EPSS 0.0102
EPSS Percentile 59.9%

Details

CWE
CWE-264
Status published
Products (1)
ibm/enovia_smarteam 5
Published Oct 15, 2008
Tracked Since Feb 18, 2026