PT-2015-1698 · Emc · Emc Documentum Webtop+4
Publicado
2015-07-16
·
Atualizado
2017-09-22
·
CVE-2015-4529
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
EMC Documentum WebTop versions prior to 6.8P02
EMC Documentum Administrator versions prior to 7.2P01
EMC Documentum Digital Assets Manager versions prior to 6.5SP6
EMC Documentum Web Publishers versions prior to 6.5SP7
EMC Documentum Task Space versions prior to 6.7SP2
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. This is related to an open redirect vulnerability in the mentioned EMC Documentum components.
Recommendations
For EMC Documentum WebTop versions prior to 6.8P02, update to version 6.8P02 or later.
For EMC Documentum Administrator versions prior to 7.2P01, update to version 7.2P01 or later.
For EMC Documentum Digital Assets Manager versions prior to 6.5SP6, update to version 6.5SP6 or later.
For EMC Documentum Web Publishers versions prior to 6.5SP7, update to version 6.5SP7 or later.
For EMC Documentum Task Space versions prior to 6.7SP2, update to version 6.7SP2 or later.
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Emc Documentum Administrator
Emc Documentum Digital Assets Manager
Emc Documentum Taskspace
Emc Documentum Web Publisher
Emc Documentum Webtop