CVE-2016-0882

EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References
Link Resource
http://seclists.org/bugtraq/2016/Feb/66 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1034993 Third Party Advisory VDB Entry
http://seclists.org/bugtraq/2016/Feb/66 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1034993 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emc:documentum_xcp:2.1:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_xcp:2.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:42

Type Values Removed Values Added
References () http://seclists.org/bugtraq/2016/Feb/66 - Third Party Advisory, VDB Entry () http://seclists.org/bugtraq/2016/Feb/66 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1034993 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1034993 - Third Party Advisory, VDB Entry

Information

Published : 2016-02-12 01:59

Updated : 2024-11-21 02:42


NVD link : CVE-2016-0882

Mitre link : CVE-2016-0882

CVE.ORG link : CVE-2016-0882


JSON object : View

Products Affected

emc

  • documentum_xcp