CVE-2015-4529
Summary
| CVE | CVE-2015-4529 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-16 21:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Open redirect vulnerability in EMC Documentum WebTop before 6.8P02, Documentum Administrator before 7.2P01, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. |
Risk And Classification
Primary CVSS: v2.0 5.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Documentum Administrator | All | All | All | All |
| Application | Emc | Documentum Digital Asset Manager | All | sp6 | All | All |
| Application | Emc | Documentum Taskspace | All | sp2 | All | All |
| Application | Emc | Documentum Webtop | All | All | All | All |
| Application | Emc | Documentum Web Publisher | All | sp7 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bugtraq: ESA-2015-123: EMC Documentum WebTop Open Redirect Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Multiple EMC Documentum Products CVE-2015-4529 Unspecified Open Redirection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| EMC Documentum WebTop Lets Remote Users Redirect the Target User to an Arbitrary Site - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.