VYPR
Unrated severityNVD Advisory· Published Mar 4, 2009· Updated Apr 23, 2026

CVE-2009-0809

CVE-2009-0809

Description

The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated users in Dassault ENOVIA SmarTeam Web Editor can read profile cards of restricted document objects via a shared link.

Vulnerability

The Web Editor component in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8 (and possibly CATIA) fails to enforce access controls when viewing the profile card of a document object. A remote authenticated user who does not have permission to a document class can still view the profile card if they receive a direct link from the object's owner. The vulnerability exists because the link bypasses the permission check for the profile card view, although the actual document viewer still enforces authorization [1].

Exploitation

An attacker must be an authenticated user of the Web Editor. The attack requires the owner of a document object (who has permission to the document class) to send a link to the attacker via the email icon in the Web Editor. The attacker then clicks the link and can view the profile card of the object, even though the attacker has no access rights to that document class. The attacker cannot view the document content itself, as the viewer returns an unauthorized error [1].

Impact

Successful exploitation allows an authenticated attacker to read the profile card (metadata) of a document object that they are not authorized to access. This results in information disclosure of potentially sensitive metadata. The actual document content remains protected. The attacker gains no additional privileges beyond their existing authenticated session [1].

Mitigation

The issue is fixed in SmarTeam V5 Release 18 Service Pack 8 (SP08). Users should upgrade to this version or later. No workaround is documented in the available reference [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • IBM/Catia3 versions
    cpe:2.3:a:ibm:catia:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ibm:catia:*:*:*:*:*:*:*:*range: <=5.18
    • cpe:2.3:a:ibm:catia:5.16:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:catia:5.17:*:*:*:*:*:*:*
  • Range: < R18SP8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.