CVE-2015-4536: Infoleak
EMC Documentum Content Server before 7.0 P20, 7.1 before P18, and 7.2 before P02, when RPC tracing is configured, stores certain obfuscated password data in a log file, which allows remote authenticated users to obtain sensitive information by reading this file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4536?
CVE-2015-4536 is considered a medium severity vulnerability due to its potential exposure of sensitive information.
How do I fix CVE-2015-4536?
To fix CVE-2015-4536, upgrade to EMC Documentum Content Server version 7.0 P20 or higher, 7.1 P18 or higher, or 7.2 P02 or higher.
Who is affected by CVE-2015-4536?
CVE-2015-4536 affects users of EMC Documentum Content Server versions 7.0, 7.1, and 7.2 prior to specified patches.
What type of data is exposed in CVE-2015-4536?
CVE-2015-4536 exposes certain obfuscated password data stored in log files due to RPC tracing.
Can remote users exploit CVE-2015-4536?
Yes, remote authenticated users could exploit CVE-2015-4536 by accessing the logs containing sensitive information.