Cross-site request forgery (CSRF) vulnerability in EMC Documentum WebTop before 6.8P01, Documentum Administrator through 7.2, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to hijack the authentication of arbitrary users. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2518.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/bugtraq/2015/Aug/87 - | |
References | () http://www.securityfocus.com/bid/76405 - |
Information
Published : 2015-08-20 10:59
Updated : 2024-11-21 02:31
NVD link : CVE-2015-4530
Mitre link : CVE-2015-4530
CVE.ORG link : CVE-2015-4530
JSON object : View
Products Affected
emc
- documentum_administrator
- documentum_taskspace
- documentum_web_publisher
- documentum_webtop
- documentum_digital_asset_manager
CWE
CWE-352
Cross-Site Request Forgery (CSRF)