PT-2015-6609 · Emc · Emc Documentum Content Server
Publicado
2015-08-20
·
Atualizado
2016-11-28
·
CVE-2015-4532
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC Documentum Content Server versions prior to 6.7SP1 P32
EMC Documentum Content Server versions 6.7SP2 prior to P25
EMC Documentum Content Server versions 7.0 prior to P19
EMC Documentum Content Server versions 7.1 prior to P16
EMC Documentum Content Server versions 7.2 prior to P02
Description
The issue allows remote authenticated users to execute arbitrary code with super-user privileges by running save RPC commands, due to improper authorization checks and insufficient restriction of object types.
Recommendations
For versions prior to 6.7SP1 P32, update to 6.7SP1 P32 or later.
For versions 6.7SP2 prior to P25, update to 6.7SP2 P25 or later.
For versions 7.0 prior to P19, update to 7.0 P19 or later.
For versions 7.1 prior to P16, update to 7.1 P16 or later.
For versions 7.2 prior to P02, update to 7.2 P02 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Emc Documentum Content Server