PT-2015-6609 · Emc · Emc Documentum Content Server

Published

2015-08-20

·

Updated

2016-11-28

·

CVE-2015-4532

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC Documentum Content Server versions prior to 6.7SP1 P32 EMC Documentum Content Server versions 6.7SP2 prior to P25 EMC Documentum Content Server versions 7.0 prior to P19 EMC Documentum Content Server versions 7.1 prior to P16 EMC Documentum Content Server versions 7.2 prior to P02
Description The issue allows remote authenticated users to execute arbitrary code with super-user privileges by running save RPC commands, due to improper authorization checks and insufficient restriction of object types.
Recommendations For versions prior to 6.7SP1 P32, update to 6.7SP1 P32 or later. For versions 6.7SP2 prior to P25, update to 6.7SP2 P25 or later. For versions 7.0 prior to P19, update to 7.0 P19 or later. For versions 7.1 prior to P16, update to 7.1 P16 or later. For versions 7.2 prior to P02, update to 7.2 P02 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4532

Affected Products

Emc Documentum Content Server