MEDIUM · 5.0

CVE-2014-4639

EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, which makes it easier for remote attackers to conduc...

Vulnerability Description

EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, which makes it easier for remote attackers to conduct phishing attacks via brute-force attempts to predict the parameter value.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
EmcDocumentum Wdk<= 6.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-4639?

CVE-2014-4639 is a vulnerability with a CVSS score of 5.0 (MEDIUM). EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, which makes it easier for remote attackers to conduc...

How severe is CVE-2014-4639?

CVE-2014-4639 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-4639?

Check the references section above for vendor advisories and patch information. Affected products include: Emc Documentum Wdk.