CVE-2015-4536
EMC Documentum Content Server Privilege Escalation / Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
EMC Documentum Content Server before 7.0 P20, 7.1 before P18, and 7.2 before P02, when RPC tracing is configured, stores certain obfuscated password data in a log file, which allows remote authenticated users to obtain sensitive information by reading this file.
Vulnerabilidad en EMC Documentum Content Server en versiones anteriores a 7.0 P20, 7.1 en versiones anteriores a P18 y 7.2 en versiones anteriores a P02, cuando está configurado el rastreo RPC, almacena ciertos datos de contraseñas ofuscadas en un archivo de registro, lo que permite a usuarios remotos autenticados obtener información sensible mediante la lectura de este archivo.
EMC Documentum Content Server contains multiple vulnerabilities that could be exploited by malicious users to compromise the Content Server in several ways.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-11 CVE Reserved
- 2015-08-17 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/bugtraq/2015/Aug/86 | Mailing List |
|
http://www.securityfocus.com/bid/76412 | Vdb Entry | |
http://www.securitytracker.com/id/1033296 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 7.0 Search vendor "Emc" for product "Documentum Content Server" and version "7.0" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 7.1 Search vendor "Emc" for product "Documentum Content Server" and version "7.1" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum Content Server Search vendor "Emc" for product "Documentum Content Server" | 7.2 Search vendor "Emc" for product "Documentum Content Server" and version "7.2" | - |
Affected
|