PT-2015-2731 · Emc · Emc Documentum Taskspace+4

Published

2015-07-04

·

Updated

2016-12-28

·

CVE-2015-4524

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EMC Documentum Administrator versions 6.7SP1 through 6.7SP1 before P31, 6.7SP2 through 6.7SP2 before P23, 7.0 through 7.0 before P18, 7.1 through 7.1 before P15, and 7.2 through 7.2 before P01 EMC Documentum Digital Asset Management version 6.5SP6 before P25 EMC Documentum TaskSpace versions 6.7SP1 through 6.7SP1 before P31 and 6.7SP2 through 6.7SP2 before P23 EMC Documentum Web Publisher version 6.5 SP7 before P25 EMC Documentum WebTop versions 6.7SP1 through 6.7SP1 before P31, 6.7SP2 through 6.7SP2 before P23, and 6.8 through 6.8 before P01
Description The issue is related to an unrestricted file upload vulnerability. This vulnerability can be exploited by a remote attacker to execute arbitrary code by uploading a file to the Content Server.
Recommendations For EMC Documentum Administrator versions 6.7SP1 through 6.7SP1 before P31, 6.7SP2 through 6.7SP2 before P23, 7.0 through 7.0 before P18, 7.1 through 7.1 before P15, and 7.2 through 7.2 before P01, update to a version that includes the necessary patches. For EMC Documentum Digital Asset Management version 6.5SP6 before P25, update to a version that includes the necessary patches. For EMC Documentum TaskSpace versions 6.7SP1 through 6.7SP1 before P31 and 6.7SP2 through 6.7SP2 before P23, update to a version that includes the necessary patches. For EMC Documentum Web Publisher version 6.5 SP7 before P25, update to a version that includes the necessary patches. For EMC Documentum WebTop versions 6.7SP1 through 6.7SP1 before P31, 6.7SP2 through 6.7SP2 before P23, and 6.8 through 6.8 before P01, update to a version that includes the necessary patches. As a temporary workaround, consider restricting file uploads to the Content Server until a patch is available.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12096
CVE-2015-4524

Affected Products

Emc Documentum Administrator
Emc Documentum Digital Asset Management
Emc Documentum Taskspace
Emc Documentum Web Publisher
Emc Documentum Webtop