VulnerabilityModified
CVE-2015-0517
The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading a…
MEDIUM 4.0EPSS 1.23%
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading a file.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- emc/documentum d2
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.htmlBroken Link
- http://www.securityfocus.com/bid/72501Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031693Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100874
- http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.htmlBroken Link
- http://www.securityfocus.com/bid/72501Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1031693Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100874
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.