PT-2013-5962 · Emc+1 · Documentum Edition+3
Published
2013-11-21
·
Updated
2015-07-22
·
CVE-2013-6177
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EMC Document Sciences xPression versions 4.1 before Patch 47
EMC Document Sciences xPression versions 4.2 before Patch 26
EMC Document Sciences xPression versions 4.5 before Patch 05
Description
A directory traversal issue allows remote authenticated users to read arbitrary files by leveraging xDashboard access. This issue affects products used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine.
Recommendations
For versions 4.1, apply Patch 47 to resolve the issue.
For versions 4.2, apply Patch 26 to resolve the issue.
For versions 4.5, apply Patch 05 to resolve the issue.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Documentum Edition
Enterprise Edition Compuset Engine
Enterprise Edition Publish Engine
Xpression