CVE-2012-0396
Summary
| CVE | CVE-2012-0396 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-02-06 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Documentum Xplore | 1.0 | All | All | All |
| Application | Emc | Documentum Xplore | 1.1 | All | All | All |
| Application | Emc | Documentum Xplore | 1.1 | p01 | All | All |
| Application | Emc | Documentum Xplore | 1.1 | p03 | All | All |
| Application | Emc | Documentum Xplore | 1.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC Documentum xPlore Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA47920 - EMC Documentum xPlore Search Result Information Disclosure Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| EMC Documentum xPlore Search Lets Remote Authenticated Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| archives.neohapsis.com/archives/bugtraq/2012-02/0020.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.