EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92906 | vdb entry |
http://www.securitytracker.com/id/1036796 | vdb entry |
http://seclists.org/bugtraq/2016/Sep/18 | third party advisory mailing list |