CVE-2009-0809

ENOVIA SmarTeam < 5.18 - Authenticated Information Disclosure via Web Editor Profile Card

Title source: llm
STIX 2.1

Description

The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34037
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0525
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33895

Scores

EPSS 0.0086
EPSS Percentile 54.6%

Details

CWE
CWE-264
Status published
Products (4)
3ds/enovia_smarteam < 5.18
ibm/catia 5.16
ibm/catia 5.17
ibm/catia < 5.18
Published Mar 04, 2009
Tracked Since Feb 18, 2026