CVE-2016-0886: Infoleak
Published Mar 9, 2016
·Updated
EMC Documentum xCP 2.1 before patch 24 and 2.2 before patch 12 allows remote authenticated users to obtain sensitive user-account metadata via a members/xcpmember API call.
Affected Software
2 affected components
EMC Documentum xCP=2.1
EMC Documentum xCP=2.2
Event History
Mar 9, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0886?
CVE-2016-0886 has a moderate severity rating as it allows remote authenticated users to access sensitive user-account metadata.
2
How do I fix CVE-2016-0886?
To fix CVE-2016-0886, apply patch 24 for Documentum xCP 2.1 or patch 12 for Documentum xCP 2.2.
3
Who is affected by CVE-2016-0886?
Users of EMC Documentum xCP versions 2.1 before patch 24 and 2.2 before patch 12 are affected by CVE-2016-0886.
4
What type of vulnerability is CVE-2016-0886?
CVE-2016-0886 is an information disclosure vulnerability impacting user-account metadata.
5
What API is involved in CVE-2016-0886?
CVE-2016-0886 involves the members/xcp_member API call that can be exploited for data exposure.