First published: Fri Sep 04 2015(Updated: )
EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows remote authenticated users to obtain superuser privileges via crafted object operations. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4626.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Documentum Content Server | =7.1 | |
EMC Documentum Content Server | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4544 has a high severity due to its potential for privilege escalation by remote authenticated users.
To fix CVE-2015-4544, upgrade EMC Documentum Content Server to version 7.1P20 or 7.2P04 or later.
CVE-2015-4544 affects users of EMC Documentum Content Server versions prior to 7.1P20 and 7.2P04.
CVE-2015-4544 allows remote authenticated users to escalate their privileges to superuser through crafted object operations.
CVE-2015-4544 was disclosed in September 2015.