CVE-2013-6177: Path Traversal
Directory traversal vulnerability in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allows remote authenticated users to read arbitrary files by leveraging xDashboard access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EMC Document Sciences xPressionto a version that resolves this vulnerability.Fixed in 4.1 SP1Patch Patch 47 - Upgrade
Upgrade
EMC Document Sciences xPressionto a version that resolves this vulnerability.Fixed in 4.2Patch Patch 26 - Upgrade
Upgrade
EMC Document Sciences xPressionto a version that resolves this vulnerability.Fixed in 4.5Patch Patch 05
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6177?
CVE-2013-6177 is classified as a medium severity vulnerability due to its ability to allow remote authenticated users to read arbitrary files.
How do I fix CVE-2013-6177?
To fix CVE-2013-6177, you should apply the appropriate patches for EMC Document Sciences xPression, specifically Patch 47 for 4.1 SP1, Patch 26 for 4.2, and Patch 05 for 4.5.
Which versions are affected by CVE-2013-6177?
CVE-2013-6177 affects EMC Document Sciences xPression versions 4.1 SP1, 4.2, and 4.5 prior to their respective patches.
Who can exploit CVE-2013-6177?
CVE-2013-6177 can be exploited by remote authenticated users granted access to the vulnerable EMC Document Sciences xPression application.
What kind of attack does CVE-2013-6177 enable?
CVE-2013-6177 enables a directory traversal attack that allows unauthorized file access on the server.