three blocks
Datacore Software

News

EMC Documentum vulnerability

posted on 11 February 2008 10:14


Error in the "dmclTrace.jsp" page

An FSIRT advisory note says: A vulnerability has been identified in EMC Documentum Administrator and Webtop, which could be exploited by attackers to take complete control of an affected system. This issue is caused by an error in the "dmclTrace.jsp" page that does not validate uploaded files, which could be exploited by attackers to upload and overwrite arbitrary files on a vulnerable server through a specially crafted HTTP request, and execute malicious code.

tags:  EMC Documentum FSIRT