CVE-2016-0914
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated…
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- emc/documentum administrator · emc/documentum capital projects · emc/documentum taskspace · emc/documentum webtop
- Source
- security_alert@emc.com
References
- http://seclists.org/bugtraq/2016/Jun/92Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036153Third Party Advisory, VDB Entry
- http://seclists.org/bugtraq/2016/Jun/92Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036153Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.