Lucene search

K
cveDellCVE-2015-4536
HistoryAug 20, 2015 - 10:59 a.m.

CVE-2015-4536

2015-08-2010:59:18
CWE-200
dell
web.nvd.nist.gov
24
cve-2015-4536
emc
documentum content server
remote access
sensitive information disclosure
rpc tracing
security vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

49.6%

EMC Documentum Content Server before 7.0 P20, 7.1 before P18, and 7.2 before P02, when RPC tracing is configured, stores certain obfuscated password data in a log file, which allows remote authenticated users to obtain sensitive information by reading this file.

Affected configurations

Nvd
Node
emcdocumentum_content_serverMatch7.0
OR
emcdocumentum_content_serverMatch7.1
OR
emcdocumentum_content_serverMatch7.2
VendorProductVersionCPE
emcdocumentum_content_server7.0cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*
emcdocumentum_content_server7.1cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*
emcdocumentum_content_server7.2cpe:2.3:a:emc:documentum_content_server:7.2:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

49.6%