VulnerabilityModified
CVE-2016-6644
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
MEDIUM 5.3EPSS 1.86%
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-264
- Affected
- emc/documentum d2
- Source
- security_alert@emc.com
References
- http://seclists.org/bugtraq/2016/Sep/18Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/92906
- http://www.securitytracker.com/id/1036796
- http://seclists.org/bugtraq/2016/Sep/18Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/92906
- http://www.securitytracker.com/id/1036796
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.