Skip to main content

Vendor archive

emc CVEs

Beta · best-effort

414 CVEs tagged to vendor emc78 Critical, 109 High, 197 Medium, 30 Low, 0 Unrated.

CVE-2014-0637

Published Apr 4, 2014

Cross-site scripting (XSS) vulnerability in the back-office case-management application in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote aut…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0635

Published Apr 1, 2014

Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0634

Published Apr 1, 2014

EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to ob…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0633

Published Apr 1, 2014

The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary co…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0632

Published Apr 1, 2014

Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0623

Published Mar 27, 2014

Cross-site scripting (XSS) vulnerability in the Self-Service Console in EMC RSA Authentication Manager 7.1 before SP4 P32 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2276

Published Mar 21, 2014

The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to the Connectrix Manager repositor…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0630

Published Mar 6, 2014

EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 allows remote authenticated users to read arbitrary files via a modified imaging-service URL.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0629

Published Mar 6, 2014

EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 does not properly handle the interaction between the dm_world group and the dm_superusers_dynamic group, whi…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0624

Published Mar 6, 2014

EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-rea…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0627

Published Feb 18, 2014

The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to trigger the selection of a weak cipher suite by using the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0626

Published Feb 18, 2014

The (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 make it easier for remote attackers to bypass intended cryptographic protection mechan…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0625

Published Feb 18, 2014

The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0622

Published Feb 6, 2014

The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 before P12, and 7.1 before P01 does not properly implement…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6182

Published Dec 28, 2013

Unquoted Windows search path vulnerability in EMC Replication Manager before 5.5 allows local users to gain privileges via a crafted application in a parent directory of an intend…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6181

Published Dec 28, 2013

EMC Watch4Net before 6.3 stores cleartext polled-device passwords in the installation repository, which allows local users to obtain sensitive information by leveraging repository…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6178

Published Dec 19, 2013

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.4 SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6810

Published Dec 12, 2013

The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advisor, and possibly other produ…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3288

Published Nov 22, 2013

Cross-site scripting (XSS) vulnerability on the EMC RSA Data Protection Manager (DPM) appliance 3.2.x before 3.2.4.2 and 3.5.x before 3.5.1 allows remote attackers to inject arbit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6177

Published Nov 21, 2013

Directory traversal vulnerability in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterpri…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6176

Published Nov 21, 2013

Multiple SQL injection vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Ent…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6175

Published Nov 21, 2013

Multiple cross-site scripting (XSS) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6174

Published Nov 21, 2013

Multiple open redirect vulnerabilities in xAdmin in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Ed…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6173

Published Nov 21, 2013

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Doc…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 414 CVEsPage 11 of 17