EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/51863 | vdb entry |
http://securitytracker.com/id?1026639 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/72994 | vdb entry |
http://secunia.com/advisories/47920 | third party advisory vendor advisory |