CVE-2014-4636: CSRF
Published Jan 7, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to hijack the authentication of arbitrary users for requests that perform Docbase operations.
Affected Software
1 affected component
EMC Documentum WDK<=6.7
Event History
Jan 7, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4636?
The severity of CVE-2014-4636 is considered high due to its potential for unauthorized access and CSRF attacks.
2
How do I fix CVE-2014-4636?
To fix CVE-2014-4636, upgrade to EMC Documentum WDK version 6.8 or later.
3
What type of vulnerability is CVE-2014-4636?
CVE-2014-4636 is a Cross-site Request Forgery (CSRF) vulnerability.
4
Who is affected by CVE-2014-4636?
Users of EMC Documentum Web Development Kit versions prior to 6.8 are affected by CVE-2014-4636.
5
What can attackers do with CVE-2014-4636?
Attackers can hijack the authentication of arbitrary users for requests that perform Docbase operations with CVE-2014-4636.