Vulnerability CVE-2015-4532


Published: 2015-08-20

Description:
EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization and does not properly restrict object types, which allows remote authenticated users to run save RPC commands with super-user privileges, and consequently execute arbitrary code, via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2514.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
EMC Documentum Content Server Code Execution
Andrey B. Panfil...
19.08.2015

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
10/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
EMC -> Documentum content server 

 References:
http://seclists.org/bugtraq/2015/Aug/86
http://www.securityfocus.com/bid/76414

Copyright 2024, cxsecurity.com

 

Back to Top