6.8

CVE-2014-2518

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Digital Assets Manager Version 6.5
Emc ≫ Digital Assets Manager Version 6.5 Update sp5
Emc ≫ Digital Assets Manager Version 6.5 Update sp6
Emc ≫ Documentum Administrator Version 6.7
Emc ≫ Documentum Administrator Version 6.7 Update sp1
Emc ≫ Documentum Administrator Version 6.7 Update sp2
Emc ≫ Documentum Administrator Version 7.0
Emc ≫ Documentum Administrator Version 7.1
Emc ≫ Documentum Records Manager Version 6.7 Update sp1
Emc ≫ Documentum Records Manager Version 6.7 Update sp2
Emc ≫ Documentum Wdk Version 6.7 Update sp1
Emc ≫ Documentum Wdk Version 6.7 Update sp2
Emc ≫ Documentum Webtop Version 6.7
Emc ≫ Documentum Webtop Version 6.7 Update sp1
Emc ≫ Documentum Webtop Version 6.7 Update sp2
Emc ≫ Task Space Version 6.7 Update sp1
Emc ≫ Task Space Version 6.7 Update sp2
Emc ≫ Web Publishers Version 6.5 Update sp6
Emc ≫ Web Publishers Version 6.5 Update sp7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.577
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://secunia.com/advisories/60563
http://www.securityfocus.com/archive/1/533159/30/0/threaded
http://www.securityfocus.com/bid/69277
http://www.securitytracker.com/id/1030742
https://exchange.xforce.ibmcloud.com/vulnerabilities/95365