CVE-2013-3286: XSS
Published Nov 6, 2013
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
6 affected components
EMC Documentum eRoom<=7.4.4
EMC Documentum eRoom=7.3.0
EMC Documentum eRoom=7.4.0
EMC Documentum eRoom=7.4.1
EMC Documentum eRoom=7.4.2
EMC Documentum eRoom=7.4.3
Event History
Nov 6, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3286?
CVE-2013-3286 is classified as a moderate severity vulnerability due to its cross-site scripting (XSS) nature.
2
How do I fix CVE-2013-3286?
To fix CVE-2013-3286, upgrade EMC Documentum eRoom to version 7.4.4 P11 or later.
3
What systems are affected by CVE-2013-3286?
CVE-2013-3286 affects EMC Documentum eRoom versions 7.4.3 and earlier, including 7.3.0 to 7.4.2.
4
What kind of attack does CVE-2013-3286 enable?
CVE-2013-3286 enables remote attackers to inject arbitrary web scripts or HTML through crafted URLs.
5
Is CVE-2013-3286 an issue in the latest version of Documentum eRoom?
No, CVE-2013-3286 is not an issue in EMC Documentum eRoom version 7.4.4 P11 or higher.