CVE-2017-2766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
03/02/2017
Last modified:
20/04/2025

Description

EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emc:documentum_eroom:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_eroom:7.4.4:sp1:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_eroom:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_eroom:7.4.5:p01:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_eroom:7.4.5:p02:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_eroom:7.4.5:p03:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_eroom:7.5.0:*:*:*:*:*:*:*