Vulnerability Description
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emc | Documentum Xcp | 2.1 |
References
- http://seclists.org/bugtraq/2016/Feb/66Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034993Third Party AdvisoryVDB Entry
- http://seclists.org/bugtraq/2016/Feb/66Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034993Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-0882?
CVE-2016-0882 is a vulnerability with a CVSS score of 5.4 (MEDIUM). EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction...
How severe is CVE-2016-0882?
CVE-2016-0882 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0882?
Check the references section above for vendor advisories and patch information. Affected products include: Emc Documentum Xcp.