PT-2015-6612 · Emc · Emc Documentum Content Server
Publicado
2015-08-20
·
Atualizado
2017-09-21
·
CVE-2015-4535
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
EMC Documentum Content Server versions prior to 6.7SP1 P32
EMC Documentum Content Server versions prior to 6.7SP2 P25
EMC Documentum Content Server versions prior to 7.0 P19
EMC Documentum Content Server versions prior to 7.1 P16
EMC Documentum Content Server versions prior to 7.2 P02
Description
The issue allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket when
debug trace is configured.Recommendations
For EMC Documentum Content Server versions prior to 6.7SP1 P32, update to version 6.7SP1 P32 or later.
For EMC Documentum Content Server versions prior to 6.7SP2 P25, update to version 6.7SP2 P25 or later.
For EMC Documentum Content Server versions prior to 7.0 P19, update to version 7.0 P19 or later.
For EMC Documentum Content Server versions prior to 7.1 P16, update to version 7.1 P16 or later.
For EMC Documentum Content Server versions prior to 7.2 P02, update to version 7.2 P02 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Emc Documentum Content Server