PT-2015-6612 · Emc · Emc Documentum Content Server

Publicado

2015-08-20

·

Atualizado

2017-09-21

·

CVE-2015-4535

CVSS v2.0

7.5

Alta

VetorAV:N/AC:M/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions EMC Documentum Content Server versions prior to 6.7SP1 P32 EMC Documentum Content Server versions prior to 6.7SP2 P25 EMC Documentum Content Server versions prior to 7.0 P19 EMC Documentum Content Server versions prior to 7.1 P16 EMC Documentum Content Server versions prior to 7.2 P02
Description The issue allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket when debug trace is configured.
Recommendations For EMC Documentum Content Server versions prior to 6.7SP1 P32, update to version 6.7SP1 P32 or later. For EMC Documentum Content Server versions prior to 6.7SP2 P25, update to version 6.7SP2 P25 or later. For EMC Documentum Content Server versions prior to 7.0 P19, update to version 7.0 P19 or later. For EMC Documentum Content Server versions prior to 7.1 P16, update to version 7.1 P16 or later. For EMC Documentum Content Server versions prior to 7.2 P02, update to version 7.2 P02 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4535

Produtos afetados

Emc Documentum Content Server