CVE Vulnerabilities

CVE-2015-4535

Published: Aug 20, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:M/Au:S/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02, when debug_trace is configured, allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket.

Affected Software

NameVendorStart VersionEnd Version
Documentum_content_serverEmc6.7-sp1 (including)6.7-sp1 (including)
Documentum_content_serverEmc6.7-sp2 (including)6.7-sp2 (including)
Documentum_content_serverEmc7.0 (including)7.0 (including)
Documentum_content_serverEmc7.1 (including)7.1 (including)
Documentum_content_serverEmc7.2 (including)7.2 (including)

References