{"api_version":"1","generated_at":"2026-07-23T22:42:42+00:00","cve":"CVE-2009-0809","urls":{"html":"https://cve.report/CVE-2009-0809","api":"https://cve.report/api/cve/CVE-2009-0809.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0809","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0809"},"summary":{"title":"CVE-2009-0809","description":"The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-03-04 17:30:02","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/34037","name":"http://secunia.com/advisories/34037","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"CATIA V5 Web Editor Unspecified Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0525","name":"http://www.vupen.com/english/advisories/2009/0525","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM HD80332: SECURITY HOLE IN WEB EDITOR - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33895","name":"http://www.securityfocus.com/bid/33895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CATIA V5 Unspecified Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0809","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0809","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"809","vulnerable":"1","versionEndIncluding":"5.18","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"3ds","cpe5":"enovia_smarteam","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"catia","cpe6":"5.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"catia","cpe6":"5.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"809","vulnerable":"1","versionEndIncluding":"5.18","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"catia","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:48:52.114Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"34037","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34037"},{"name":"ADV-2009-0525","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0525"},{"name":"HD80332","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332"},{"name":"33895","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33895"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-03-04T17:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"34037","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34037"},{"name":"ADV-2009-0525","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0525"},{"name":"HD80332","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332"},{"name":"33895","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33895"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0809","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"34037","refsource":"SECUNIA","url":"http://secunia.com/advisories/34037"},{"name":"ADV-2009-0525","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0525"},{"name":"HD80332","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332"},{"name":"33895","refsource":"BID","url":"http://www.securityfocus.com/bid/33895"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0809","datePublished":"2009-03-04T17:00:00.000Z","dateReserved":"2009-03-04T00:00:00.000Z","dateUpdated":"2024-09-16T20:28:01.214Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-04 17:30:02","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:3ds:enovia_smarteam:*:*:*:*:*:*:*:*","versionEndIncluding":"5.18","matchCriteriaId":"707448B9-31A9-43DE-9FA2-AF23B5D9F479"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:catia:*:*:*:*:*:*:*:*","versionEndIncluding":"5.18","matchCriteriaId":"DBA8D3F2-FF39-481D-B90E-DE09AE61C2EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:catia:5.16:*:*:*:*:*:*:*","matchCriteriaId":"3E3F5AE9-4DCE-4392-BF82-8C856EE69497"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:catia:5.17:*:*:*:*:*:*:*","matchCriteriaId":"E902E409-FB08-4A09-A3F4-8AF113FB3329"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"809","Ordinal":"1","Title":"CVE-2009-0809","CVE":"CVE-2009-0809","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"809","Ordinal":"1","NoteData":"The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.","Type":"Description","Title":"CVE-2009-0809"},{"CveYear":"2009","CveId":"809","Ordinal":"2","NoteData":"2009-03-04","Type":"Other","Title":"Published"}]}}}