EMC Documentum D2 < 4.6 Insufficient ACL Remote Object Manipulation (ESA-2016-034)

high Nessus Plugin ID 90422

Synopsis

The remote host is affected by a security bypass vulnerability.

Description

The remote host is running a version EMC Documentum D2 that is prior to 4.6. It is, therefore, affected by a security bypass vulnerability due to a failure to set secure access control lists (ACLs) for D2 configuration objects. An authenticated, remote attacker can exploit this to modify or delete D2 objects.

Solution

Upgrade to EMC Documentum D2 version 4.6 later.

See Also

https://seclists.org/bugtraq/2016/Apr/att-20/ESA-2016-034.txt

Plugin Details

Severity: High

ID: 90422

File Name: emc_documentum_d2_ESA-2016-034.nasl

Version: 1.8

Type: remote

Family: Misc.

Published: 4/8/2016

Updated: 11/20/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2016-0888

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:emc:documentum_d2

Required KB Items: installed_sw/EMC Documentum D2

Exploit Ease: No known exploits are available

Patch Publication Date: 3/29/2016

Vulnerability Publication Date: 3/29/2016

Reference Information

CVE: CVE-2016-0888

BID: 85808