The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/45943 | vdb entry |
http://www-1.ibm.com/support/docview.wss?uid=swg1HD71425 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg27012567&aid=1 | vendor advisory |
http://www.securityfocus.com/bid/31748 | vdb entry |
http://secunia.com/advisories/32105 | third party advisory vendor advisory |