CVE-2015-0549: XSS
Published Jun 28, 2015
·Updated
Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before 4.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
EMC Documentum D2<=4.2
Event History
Jun 28, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0549?
CVE-2015-0549 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-0549?
To fix CVE-2015-0549, upgrade EMC Documentum D2 to version 4.5 or later.
3
Who is affected by CVE-2015-0549?
Remote authenticated users of EMC Documentum D2 versions prior to 4.5 are affected by CVE-2015-0549.
4
What types of attacks are possible with CVE-2015-0549?
CVE-2015-0549 allows attackers to inject arbitrary web scripts or HTML, leading to potential data theft or session hijacking.
5
Is CVE-2015-0549 still a risk if I am using the latest version of EMC Documentum D2?
No, if you are using EMC Documentum D2 version 4.5 or later, CVE-2015-0549 is not a risk.