PT-2015-1698 · Emc · Emc Documentum Webtop+4

Publicado

2015-07-16

·

Atualizado

2017-09-22

·

CVE-2015-4529

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions EMC Documentum WebTop versions prior to 6.8P02 EMC Documentum Administrator versions prior to 7.2P01 EMC Documentum Digital Assets Manager versions prior to 6.5SP6 EMC Documentum Web Publishers versions prior to 6.5SP7 EMC Documentum Task Space versions prior to 6.7SP2
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. This is related to an open redirect vulnerability in the mentioned EMC Documentum components.
Recommendations For EMC Documentum WebTop versions prior to 6.8P02, update to version 6.8P02 or later. For EMC Documentum Administrator versions prior to 7.2P01, update to version 7.2P01 or later. For EMC Documentum Digital Assets Manager versions prior to 6.5SP6, update to version 6.5SP6 or later. For EMC Documentum Web Publishers versions prior to 6.5SP7, update to version 6.5SP7 or later. For EMC Documentum Task Space versions prior to 6.7SP2, update to version 6.7SP2 or later.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11044
CVE-2015-4529

Produtos afetados

Emc Documentum Administrator
Emc Documentum Digital Assets Manager
Emc Documentum Taskspace
Emc Documentum Web Publisher
Emc Documentum Webtop