ZeroHour

CVE-2016-0881

CVSS 3.0
6.5 medium
EPSS
2%p76
Published
()
Modified
Description

EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request.

Vendors
emc
Products
documentum xcp
Weakness
CWE-74
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.