6.5

CVE-2016-0914

EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Documentum Administrator Version 7.0
Emc ≫ Documentum Administrator Version 7.1
Emc ≫ Documentum Administrator Version 7.2
Emc ≫ Documentum Capital Projects Version 1.10
Emc ≫ Documentum Taskspace Version 6.7 Update sp3
Emc ≫ Documentum Webtop Version 6.8
Emc ≫ Documentum Webtop Version 6.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.668
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 2.8 3.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://seclists.org/bugtraq/2016/Jun/92
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036153
Third Party Advisory
VDB Entry