Skip to main content

Vendor archive

emc CVEs

Beta · best-effort

414 CVEs tagged to vendor emc78 Critical, 109 High, 197 Medium, 30 Low, 0 Unrated.

CVE-2015-0515

Published Jan 21, 2015

Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0514

Published Jan 21, 2015

EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0513

Published Jan 21, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticat…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4639

Published Jan 7, 2015

EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, which makes it easier for remot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4638

Published Jan 7, 2015

EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame-injection attacks and obtain sensitive information via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4637

Published Jan 7, 2015

Open redirect vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4636

Published Jan 7, 2015

Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to hijack the authentication of arbitrary users for…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4635

Published Jan 7, 2015

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum Web Development Kit (WDK) before 6.8 allow remote attackers to inject arbitrary web script or HTML via unspec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4634

Published Dec 30, 2014

Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows local users to gain privileges via a Trojan horse application w…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4626

Published Dec 17, 2014

EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a comm…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4633

Published Dec 12, 2014

Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4628

Published Dec 12, 2014

Cross-site scripting (XSS) vulnerability in EMC Isilon InsightIQ 2.x and 3.x before 3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2516

Published Dec 12, 2014

Open redirect vulnerability in EMC RSA Authentication Manager 8.x before 8.1 Patch 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4631

Published Dec 8, 2014

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4629

Published Dec 6, 2014

EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via unspecified vectors related t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4623

Published Oct 25, 2014

EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4620

Published Oct 25, 2014

The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmed…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4622

Published Sep 17, 2014

EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4621

Published Sep 17, 2014

EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows re…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4619

Published Aug 28, 2014

EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, all…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4618

Published Aug 20, 2014

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to gain privileges via a user-created system object.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2521

Published Aug 20, 2014

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensitive object metadata via an RPC command.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2520

Published Aug 20, 2014

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated user…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2518

Published Aug 20, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arb…

CVSS 6.8 · Medium

CVE-2014-2517

Published Aug 20, 2014

Unspecified vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to gain privileges via unknown vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 414 CVEsPage 9 of 17