CVE-2016-0881: Medium severity emc documentum xcp vulnerability
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0881?
CVE-2016-0881 is considered a critical vulnerability due to the potential for remote authenticated users to exploit it and access sensitive data.
How do I fix CVE-2016-0881?
To mitigate CVE-2016-0881, apply patch 23 for version 2.1 and patch 11 for version 2.2 of EMC Documentum xCP.
Who is affected by CVE-2016-0881?
CVE-2016-0881 affects users of EMC Documentum xCP versions 2.1 prior to patch 23 and 2.2 prior to patch 11.
What type of attack does CVE-2016-0881 enable?
CVE-2016-0881 enables Documentum Query Language (DQL) injection attacks that can compromise sensitive repository information.
Can CVE-2016-0881 be exploited remotely?
Yes, CVE-2016-0881 can be exploited by remote authenticated users, making it a significant security concern.