CVE-2015-4537: Infoleak
Lockbox in EMC Documentum D2 before 4.5 uses a hardcoded passphrase when a server lacks a D2.Lockbox file, which makes it easier for remote authenticated users to decrypt admin tickets by locating this passphrase in a decompiled D2 JAR archive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4537?
CVE-2015-4537 is classified as a medium severity vulnerability due to the risk of remote authenticated users being able to decrypt admin tickets.
How do I fix CVE-2015-4537?
To fix CVE-2015-4537, ensure that the D2.Lockbox file is present on your server to avoid using the hardcoded passphrase.
Who is affected by CVE-2015-4537?
CVE-2015-4537 affects users of EMC Documentum D2 versions up to and including 4.4.
What type of vulnerability is CVE-2015-4537?
CVE-2015-4537 is a cryptographic vulnerability resulting from the presence of a hardcoded passphrase.
Can CVE-2015-4537 be exploited remotely?
Yes, CVE-2015-4537 can be exploited remotely by authenticated users with access to certain components of the system.