CVE-2015-4535
EMC Documentum Content Server Privilege Escalation / Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02, when __debug_trace__ is configured, allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket.
Vulnerabilidad en Java Method Server (JMS) en EMC Documentum Content Server en versiones anteriores a 6.7SP1 P32, 6.7SP2 en versiones anteriores a P25, 7.0 en versiones anteriores a P19, 7.1 en versiones anteriores a P16 y 7.2 en versiones anteriores a P02, cuando está configurado __debug_trace__, permite a usuarios remotos autenticados conseguir privilegios de superusuario aprovechándose de la capacidad para leer un archivo de registro que contiene un ticket de registro.
EMC Documentum Content Server contains multiple vulnerabilities that could be exploited by malicious users to compromise the Content Server in several ways.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-11 CVE Reserved
- 2015-08-17 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/bugtraq/2015/Aug/86 | Mailing List |
|
http://www.securityfocus.com/bid/76409 | Vdb Entry | |
http://www.securitytracker.com/id/1033296 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 6.7 Search vendor "Emc" for product "Documentum Content Server" and version "6.7" | sp1 |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 6.7 Search vendor "Emc" for product "Documentum Content Server" and version "6.7" | sp2 |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 7.0 Search vendor "Emc" for product "Documentum Content Server" and version "7.0" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 7.1 Search vendor "Emc" for product "Documentum Content Server" and version "7.1" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 7.2 Search vendor "Emc" for product "Documentum Content Server" and version "7.2" | - |
Affected
|