The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.
References
Link | Resource |
---|---|
http://secunia.com/advisories/32105 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg27012567&aid=1 | Vendor Advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1HD71425 | Vendor Advisory |
http://www.securityfocus.com/bid/31748 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45943 |
Configurations
History
No history.
Information
Published : 2008-10-15 20:08
Updated : 2024-02-04 17:33
NVD link : CVE-2008-4581
Mitre link : CVE-2008-4581
CVE.ORG link : CVE-2008-4581
JSON object : View
Products Affected
ibm
- enovia_smarteam
CWE
CWE-264
Permissions, Privileges, and Access Controls