PT-2011-4051 · Emc · Emc Documentum Eroom
Published
2011-11-09
·
Updated
2012-02-14
·
CVE-2011-2739
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC Documentum eRoom versions 7.3.x through 7.4.x before 7.4.3.g
EMC Documentum eRoom version 7.4.x before 7.4.3.g can be omitted as it is already included in the range, so the final output is:
EMC Documentum eRoom versions 7.3.x through 7.4.x before 7.4.3.g can be further simplified to:
EMC Documentum eRoom versions 7.3.x through 7.4.2
However, to maintain the original meaning and include all versions up to but not including 7.4.3.g, the correct simplification is:
EMC Documentum eRoom versions 7.3.x through 7.4.2
But to be more precise with the given information:
EMC Documentum eRoom versions 7.3.x through 7.4.x before 7.4.3.g
Description
The file-blocking feature does not properly restrict the uploading and opening of files with dangerous file types, allowing remote authenticated users to execute arbitrary code via an uploaded file.
Recommendations
For EMC Documentum eRoom versions 7.3.x through 7.4.x before 7.4.3.g, update to version 7.4.3.g or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Documentum Eroom