VYPR

Enovia Smarteam

by IBM

CVEs (3)

  • CVE-2010-0959Mar 10, 2010
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.

  • CVE-2009-0809Mar 4, 2009
    risk 0.00cvss epss 0.00

    The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document…

  • CVE-2008-4581Oct 15, 2008
    risk 0.00cvss epss 0.00

    The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.