CVE-2009-0809
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from…
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
- EPSS
- 0.86% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- 3ds/enovia smarteam · ibm/catia
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/34037Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332Vendor Advisory
- http://www.securityfocus.com/bid/33895
- http://www.vupen.com/english/advisories/2009/0525Vendor Advisory
- http://secunia.com/advisories/34037Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332Vendor Advisory
- http://www.securityfocus.com/bid/33895
- http://www.vupen.com/english/advisories/2009/0525Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.