EMC Documentum D2 multiple DQL Injection Vulnerabilities (CVE-2015-0548)
EMC Documentum D2 multiple DQL Injection Vulnerabilities (CVE-2015-0548)
Release date:
Updated on:
Affected Systems:
EMC Documentum D2 4.5
EMC Documentum D2 4.2
EMC Documentum D2 4.1
Description:
CVE (CAN) ID: CVE-2015-0548
EMC Documentum D2 is an advanced, intuitive, configurable, and content-centric Documentum client that accelerates adoption of ECM applications.
EMC Documentum D2 has the DQL injection vulnerability in the D2DownloadService. getDownloadUrls service method, which can cause database information leakage.
<* Source: Ionut Popescu
Link: http://www.securityfocus.com/archive/1/535898
*>
Suggestion:
Vendor patch:
EMC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://emc.subscribenet.com/control/dctm/index? Manu = DCTMD2
This article permanently updates the link address: