PT-2015-1698 · Emc · Emc Documentum Webtop+4
Published
2015-07-16
·
Updated
2017-09-22
·
CVE-2015-4529
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
EMC Documentum WebTop versions prior to 6.8P02
EMC Documentum Administrator versions prior to 7.2P01
EMC Documentum Digital Assets Manager versions prior to 6.5SP6
EMC Documentum Web Publishers versions prior to 6.5SP7
EMC Documentum Task Space versions prior to 6.7SP2
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. This is related to an open redirect vulnerability in the mentioned EMC Documentum components.
Recommendations
For EMC Documentum WebTop versions prior to 6.8P02, update to version 6.8P02 or later.
For EMC Documentum Administrator versions prior to 7.2P01, update to version 7.2P01 or later.
For EMC Documentum Digital Assets Manager versions prior to 6.5SP6, update to version 6.5SP6 or later.
For EMC Documentum Web Publishers versions prior to 6.5SP7, update to version 6.5SP7 or later.
For EMC Documentum Task Space versions prior to 6.7SP2, update to version 6.7SP2 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Documentum Administrator
Emc Documentum Digital Assets Manager
Emc Documentum Taskspace
Emc Documentum Web Publisher
Emc Documentum Webtop