CVE-2015-4534
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
20/08/2015
Last modified:
12/04/2025
Description
Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 allows remote authenticated users to execute arbitrary code by forging a signature for a query string that lacks the method_verb parameter.
Impact
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:emc:documentum_content_server:6.7:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:emc:documentum_content_server:7.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page