The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/31748 | |
http://secunia.com/advisories/32105 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg27012567&aid=1 | Vendor Advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1HD71425 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45943 |
Configurations
Information
Published : 2008-10-15 13:08
Updated : 2017-08-07 18:32
NVD link : CVE-2008-4581
Mitre link : CVE-2008-4581
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- enovia_smarteam