{"api_version":"1","generated_at":"2026-07-23T01:26:56+00:00","cve":"CVE-2012-0396","urls":{"html":"https://cve.report/CVE-2012-0396","api":"https://cve.report/api/cve/CVE-2012-0396.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-0396","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-0396"},"summary":{"title":"CVE-2012-0396","description":"EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.","state":"PUBLISHED","assigner":"dell","published_at":"2012-02-06 20:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/51863","name":"http://www.securityfocus.com/bid/51863","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum xPlore Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/47920","name":"http://secunia.com/advisories/47920","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA47920 - EMC Documentum xPlore Search Result Information Disclosure Security Issue - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72994","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72994","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1026639","name":"http://securitytracker.com/id?1026639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum xPlore Search Lets Remote Authenticated Users Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html","name":"http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-0396","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-0396","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"396","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_xplore","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"396","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_xplore","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"396","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_xplore","cpe6":"1.1","cpe7":"p01","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"396","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_xplore","cpe6":"1.1","cpe7":"p03","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"396","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_xplore","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:23:31.016Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"51863","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/51863"},{"name":"1026639","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1026639"},{"name":"20120203 ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html"},{"name":"emc-documentum-info-disc(72994)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72994"},{"name":"47920","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47920"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-02-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"51863","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/51863"},{"name":"1026639","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1026639"},{"name":"20120203 ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html"},{"name":"emc-documentum-info-disc(72994)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72994"},{"name":"47920","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47920"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2012-0396","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"51863","refsource":"BID","url":"http://www.securityfocus.com/bid/51863"},{"name":"1026639","refsource":"SECTRACK","url":"http://securitytracker.com/id?1026639"},{"name":"20120203 ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html"},{"name":"emc-documentum-info-disc(72994)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72994"},{"name":"47920","refsource":"SECUNIA","url":"http://secunia.com/advisories/47920"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2012-0396","datePublished":"2012-02-06T20:00:00.000Z","dateReserved":"2012-01-09T00:00:00.000Z","dateUpdated":"2024-08-06T18:23:31.016Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-02-06 20:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_xplore:1.0:*:*:*:*:*:*:*","matchCriteriaId":"F726F284-9D94-4255-82F9-3CFB41C71BFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_xplore:1.1:*:*:*:*:*:*:*","matchCriteriaId":"DB0BD961-2EF4-41B9-B027-7CBCEAA1835F"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_xplore:1.1:p01:*:*:*:*:*:*","matchCriteriaId":"47E1CE7C-A9FA-4939-BBC5-31DF8A1BC167"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_xplore:1.1:p03:*:*:*:*:*:*","matchCriteriaId":"73CEF3A0-A18D-46E9-8F5F-3371F2831DA9"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_xplore:1.2:*:*:*:*:*:*:*","matchCriteriaId":"FB79DB4E-2381-4698-9316-9410798EA79D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"396","Ordinal":"1","Title":"CVE-2012-0396","CVE":"CVE-2012-0396","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"396","Ordinal":"1","NoteData":"EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.","Type":"Description","Title":"CVE-2012-0396"},{"CveYear":"2012","CveId":"396","Ordinal":"2","NoteData":"2012-02-06","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"396","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}