CVE-2016-0882: Medium severity emc documentum xcp vulnerability
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0882?
CVE-2016-0882 has been classified as a medium-severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2016-0882?
To mitigate CVE-2016-0882, apply patch 23 for Documentum xCP 2.1 or patch 11 for Documentum xCP 2.2.
What types of systems are affected by CVE-2016-0882?
CVE-2016-0882 affects EMC Documentum xCP versions 2.1 before patch 23 and 2.2 before patch 11.
Can CVE-2016-0882 be exploited remotely?
Yes, CVE-2016-0882 can be exploited by remote authenticated users to read arbitrary files.
What is the cause of the vulnerability in CVE-2016-0882?
The vulnerability in CVE-2016-0882 is due to improper handling of XML external entity declarations, leading to an XML External Entity (XXE) issue.