VulnerabilityModified
CVE-2012-0396
EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.
MEDIUM 4.0EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- emc/documentum xplore
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html
- http://secunia.com/advisories/47920Vendor Advisory
- http://securitytracker.com/id?1026639
- http://www.securityfocus.com/bid/51863
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72994
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html
- http://secunia.com/advisories/47920Vendor Advisory
- http://securitytracker.com/id?1026639
- http://www.securityfocus.com/bid/51863
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72994
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.