Vulnerability index

Browse CVEs

300 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Documentum Content Server HIGH 8.5
CVE-2014-2506

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to obtain …

Fix: after 6.7
Fix from $1,950 2014-06-08
Documentum Content Server HIGH 8.5
CVE-2014-2507

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute…

Fix: after 6.7
Fix from $1,950 2014-06-08
Documentum Content Server HIGH 7.5
CVE-2014-2508

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to conduct…

Fix: after 6.7
Fix from $1,950 2014-06-08
Documentum Digital Asset Manager HIGH 7.5
CVE-2014-2503

The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to…

No fix yet
Fix from $1,950 2014-06-06
Documentum D2 HIGH 9.0
CVE-2014-2504

EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass …

Mitigation only
Fix from $1,950 2014-05-26
Rsa Netwitness HIGH 7.6
CVE-2014-0643

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a …

Fix: 9.8.5.19 / 10.2.4+
Fix from $1,950 2014-05-16
Rsa Access Manager MEDIUM 6.9
CVE-2014-0646

The runtime WS component in the server in EMC RSA Access Manager 6.1.3 before 6.1.3.39, 6.1.4 before 6.1.4.22, 6.2.0 before 6.2.0.11, and 6.2.1 befor…

Mitigation only
Fix from $1,600 2014-05-01
Cloud Tiering Appliance Software HIGH 7.8
CVE-2014-0644EPSS 53%

EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external …

Mitigation only
Fix from $1,950 2014-04-17
Documentum Content Server MEDIUM 5.5
CVE-2014-0642

EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote authenticated users to bypass …

Fix: after 6.7
Fix from $1,600 2014-04-15
Vplex Geosynchrony HIGH 7.7
CVE-2014-0633

The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote att…

Mitigation only
Fix from $1,950 2014-04-01
Vplex Geosynchrony HIGH 7.5
CVE-2014-0635

Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vector…

Mitigation only
Fix from $1,950 2014-04-01
Vplex Geosynchrony MEDIUM 6.0
CVE-2014-0634

EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it eas…

Mitigation only
Fix from $1,600 2014-04-01
Vplex Geosynchrony HIGH 9.0
CVE-2014-0632

Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via un…

Mitigation only
Fix from $1,950 2014-04-01
Connectrix Manager MEDIUM 5.0
CVE-2014-2276

The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to th…

Fix: after 12.1.2
Fix from $1,600 2014-03-21
Documentum Taskspace HIGH 8.5
CVE-2014-0629

EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 does not properly handle the interaction between the dm_world group and the dm…

Mitigation only
Fix from $1,950 2014-03-06
Documentum Foundation Services HIGH 9.0
CVE-2014-0622

The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 before P12, and 7.1 before P0…

Mitigation only
Fix from $1,950 2014-02-06
Replication Manager HIGH 7.2
CVE-2013-6182

Unquoted Windows search path vulnerability in EMC Replication Manager before 5.5 allows local users to gain privileges via a crafted application in a…

Fix: after 5.4
Fix from $1,950 2013-12-28
Connectrix Manager HIGH 10.0
CVE-2013-6810EPSS 17%

The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Adv…

Mitigation only
Fix from $1,950 2013-12-12
Rsa Netwitness Nextgen MEDIUM 6.8
CVE-2013-6180

EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI…

Mitigation only
Fix from $1,600 2013-12-09
Document Sciences Xpression MEDIUM 6.8
CVE-2013-6173

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 b…

No fix yet
Fix from $1,600 2013-11-21
Document Sciences Xpression MEDIUM 6.5
CVE-2013-6176

Multiple SQL injection vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as u…

No fix yet
Fix from $1,600 2013-11-21
Document Sciences Xpression MEDIUM 5.8
CVE-2013-6174

Multiple open redirect vulnerabilities in xAdmin in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patc…

No fix yet
Fix from $1,600 2013-11-21
Rsa Authentication Agent HIGH 7.5
CVE-2013-3280

EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to by…

Mitigation only
Fix from $1,950 2013-10-25
Atmos MEDIUM 5.0
CVE-2013-3279

EMC Atmos before 2.1.4 has a blank password for the PostgreSQL account, which allows remote attackers to obtain sensitive administrative information …

Fix: after 2.1.3
Fix from $1,600 2013-10-16
Rsa Archer Egrc MEDIUM 6.0
CVE-2013-3276

EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deact…

Mitigation only
Fix from $1,600 2013-09-05
Rsa Archer Egrc MEDIUM 5.8
CVE-2013-3277

Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

Mitigation only
Fix from $1,600 2013-09-05
Rsa Authentication Agent MEDIUM 5.0
CVE-2013-3271

EMC RSA Authentication Agent for PAM 7.0 before 7.0.2.1 enforces the maximum number of login attempts within the PAM-enabled application codebase, in…

Mitigation only
Fix from $1,600 2013-08-28
Avamar Server HIGH 9.0
CVE-2013-3274

EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for cal…

Fix: after 6.1
Fix from $1,950 2013-07-19
Vnx Control Station MEDIUM 6.8
CVE-2013-3270

EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, w…

Fix: after 7.1.70.1
Fix from $1,600 2013-05-20
Alphastor HIGH 9.3
CVE-2013-0946EPSS 29%

Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via craf…

No fix yet
Fix from $1,950 2013-05-10