VulnerabilityModified
CVE-2014-4636
Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to hijack the authentication of arbitrary users for requests that perform Docbase operations.
MEDIUM 6.8EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to hijack the authentication of arbitrary users for requests that perform Docbase operations.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- emc/documentum wdk
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2015-01/0009.html
- http://packetstormsecurity.com/files/129822/EMC-Documentum-Web-Development-Kit-XSS-CSRF-Redirection-Injection.html
- http://www.securitytracker.com/id/1031497
- http://archives.neohapsis.com/archives/bugtraq/2015-01/0009.html
- http://packetstormsecurity.com/files/129822/EMC-Documentum-Web-Development-Kit-XSS-CSRF-Redirection-Injection.html
- http://www.securitytracker.com/id/1031497
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.