CVE-2016-6644: Infoleak
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an robjectid value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6644?
CVE-2016-6644 is classified as a medium severity vulnerability due to its potential for unauthorized access to documents.
How do I fix CVE-2016-6644?
To fix CVE-2016-6644, you should apply patch 15 for version 4.5 or patch 03 for version 4.6 of EMC Documentum D2.
What type of attacks does CVE-2016-6644 enable?
CVE-2016-6644 enables remote attackers to read arbitrary Docbase documents by exploiting knowledge of the r_object_id value.
Which versions of EMC Documentum D2 are affected by CVE-2016-6644?
CVE-2016-6644 affects EMC Documentum D2 versions 4.5 before patch 15 and 4.6 before patch 03.
Who is affected by CVE-2016-6644?
Organizations using vulnerable versions of EMC Documentum D2 are at risk from CVE-2016-6644 if they have not applied the necessary patches.