2024-11-23 01:05:45 +00:00

92 lines
2.8 KiB
JSON

{
"id": "CVE-2015-4537",
"sourceIdentifier": "security_alert@emc.com",
"published": "2015-08-22T18:59:02.280",
"lastModified": "2024-11-21T02:31:17.783",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Lockbox in EMC Documentum D2 before 4.5 uses a hardcoded passphrase when a server lacks a D2.Lockbox file, which makes it easier for remote authenticated users to decrypt admin tickets by locating this passphrase in a decompiled D2 JAR archive."
},
{
"lang": "es",
"value": "Vulnerabilidad en Lockbox en EMC Documentum D2 anterior a 4.5, utiliza una frase de acceso embebida cuando a un servidor le falta el fichero D2.Lockbox, lo que hace que sea m\u00e1s f\u00e1cil para los usuarios remotos autenticados descifrar tickets de administraci\u00f3n mediante la localizaci\u00f3n de esta frase de acceso en un archivo D2 JAR descompilado."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
"baseScore": 3.5,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.8,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_d2:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.4",
"matchCriteriaId": "DCFDBE2F-7E8A-4112-8A4B-AA43693EABE3"
}
]
}
]
}
],
"references": [
{
"url": "http://seclists.org/bugtraq/2015/Aug/117",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securitytracker.com/id/1033345",
"source": "security_alert@emc.com"
},
{
"url": "http://seclists.org/bugtraq/2015/Aug/117",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1033345",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}