PT-2015-1698 · Emc · Emc Documentum Webtop+4

Published

2015-07-16

·

Updated

2017-09-22

·

CVE-2015-4529

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions EMC Documentum WebTop versions prior to 6.8P02 EMC Documentum Administrator versions prior to 7.2P01 EMC Documentum Digital Assets Manager versions prior to 6.5SP6 EMC Documentum Web Publishers versions prior to 6.5SP7 EMC Documentum Task Space versions prior to 6.7SP2
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. This is related to an open redirect vulnerability in the mentioned EMC Documentum components.
Recommendations For EMC Documentum WebTop versions prior to 6.8P02, update to version 6.8P02 or later. For EMC Documentum Administrator versions prior to 7.2P01, update to version 7.2P01 or later. For EMC Documentum Digital Assets Manager versions prior to 6.5SP6, update to version 6.5SP6 or later. For EMC Documentum Web Publishers versions prior to 6.5SP7, update to version 6.5SP7 or later. For EMC Documentum Task Space versions prior to 6.7SP2, update to version 6.7SP2 or later.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11044
CVE-2015-4529

Affected Products

Emc Documentum Administrator
Emc Documentum Digital Assets Manager
Emc Documentum Taskspace
Emc Documentum Web Publisher
Emc Documentum Webtop