安全研究

安全漏洞
EMC Documentum WebTop客户端产品任意文件上传漏洞(CVE-2015-4524)

发布日期:2015-07-01
更新日期:2015-07-02

受影响系统:
EMC Documentum Webtop 6.8
EMC Documentum Webtop 6.7SP2
EMC Documentum Webtop 6.7SP1
描述:
CVE(CAN) ID: CVE-2015-4524

EMC Documentum WebTop是基于浏览器的接口,提供对EMC Documentum库及企业内容管理服务的访问。

EMC Documentum WebTop客户端产品存在任意文件上传漏洞,攻击者利用这些漏洞可向后端内容服务器上传任意类型的文件。

<*来源:EMC
  
  链接:http://www.securityfocus.com/archive/1/535897
*>

建议:
厂商补丁:

EMC
---
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

EMC Documentum WebTop 

6.7SP1 - https://emc.subscribenet.com/control/dctm/download?element=3887191

6.7SP2 - https://emc.subscribenet.com/control/dctm/download?element=4544381

6.8 - https://emc.subscribenet.com/control/dctm/download?element=5950091

EMC Documentum Capital Projects 

1.8 - https://emc.subscribenet.com/control/dctm/download?element=4928521

1.9 - https://emc.subscribenet.com/control/dctm/download?element=5350311

EMC Documentum Administrator 

6.7SP1 - https://emc.subscribenet.com/control/dctm/download?element=3887141

6.7SP2 - https://emc.subscribenet.com/control/dctm/download?element=4541681

7.0 - https://emc.subscribenet.com/control/dctm/download?element=4787271

7.1 - https://emc.subscribenet.com/control/dctm/download?element=5096401

7.2 - https://emc.subscribenet.com/control/dctm/download?element=6091351

EMC Documentum Digital Assets Manager, v6.5SP6P25或更高版本

https://emc.subscribenet.com/control/dctm/download?element=4772311

EMC Documentum Web Publishers, v6.5SP7P25或更高版本
https://emc.subscribenet.com/control/dctm/download?element=4772271

EMC Documentum Task Space 

6.7SP1  https://emc.subscribenet.com/control/dctm/download?element=3887341

6.7SP2  https://emc.subscribenet.com/control/dctm/download?element=4544451

浏览次数:1927
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障