CVE-2009-0809
ENOVIA SmarTeam < 5.18 - Authenticated Information Disclosure via Web Editor Profile Card
Title source: llmDescription
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34037
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0525
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/33895
Scores
EPSS
0.0086
EPSS Percentile
54.6%
Details
CWE
CWE-264
Status
published
Products (4)
3ds/enovia_smarteam
< 5.18
ibm/catia
5.16
ibm/catia
5.17
ibm/catia
< 5.18
Published
Mar 04, 2009
Tracked Since
Feb 18, 2026