HIGH · 9.0

CVE-2015-4544

EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows remote authenticated users to obtain superuser privile...

Vulnerability Description

EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows remote authenticated users to obtain superuser privileges via crafted object operations. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4626.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
EmcDocumentum Content Server7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4544?

CVE-2015-4544 is a vulnerability with a CVSS score of 9.0 (HIGH). EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows remote authenticated users to obtain superuser privile...

How severe is CVE-2015-4544?

CVE-2015-4544 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4544?

Check the references section above for vendor advisories and patch information. Affected products include: Emc Documentum Content Server.