PT-2013-5962 · Emc+1 · Documentum Edition+3
Publicado
2013-11-21
·
Atualizado
2015-07-22
·
CVE-2013-6177
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EMC Document Sciences xPression versions 4.1 before Patch 47
EMC Document Sciences xPression versions 4.2 before Patch 26
EMC Document Sciences xPression versions 4.5 before Patch 05
Description
A directory traversal issue allows remote authenticated users to read arbitrary files by leveraging xDashboard access. This issue affects products used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine.
Recommendations
For versions 4.1, apply Patch 47 to resolve the issue.
For versions 4.2, apply Patch 26 to resolve the issue.
For versions 4.5, apply Patch 05 to resolve the issue.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Documentum Edition
Enterprise Edition Compuset Engine
Enterprise Edition Publish Engine
Xpression