EMC Documentum Content Server Insecure Direct Object Reference (ESA-2014-156)

High Nessus Plugin ID 79720


The remote host is affected by an insecure direct object reference vulnerability.


The remote host is running a version of EMC Documentum Content Server that is affected by an insecure direct object reference vulnerability, which allows a remote, authenticated attacker to potentially read or delete arbitrary files without authorization.


Apply the relevant patch referenced in the vendor advisory.

See Also


Plugin Details

Severity: High

ID: 79720

File Name: emc_documentum_content_server_ESA-2014-156.nasl

Version: $Revision: 1.1 $

Type: local

Agent: windows

Family: Windows

Published: 2014/12/04

Modified: 2014/12/04

Dependencies: 77631

Risk Information

Risk Factor: High


Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:P/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:emc:documentum_content_server

Required KB Items: installed_sw/EMC Documentum Content Server

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/12/02

Vulnerability Publication Date: 2014/12/02

Reference Information

CVE: CVE-2014-4629

BID: 71422