Executive brief
Multiple EMC Documentum web applications, used for enterprise content management and administration, are vulnerable to a security flaw where malicious scripts can be stored on the server. If an unsuspecting user views the affected page, these scripts could execute in their browser, potentially allowing an attacker to hijack sessions or steal sensitive information. This impact can compromise the integrity of user interactions with the document management system.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in several EMC Documentum web interfaces, including WebTop, TaskSpace, Capital Projects, and Administrator. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker can exploit this by injecting malicious scripts into the application that are subsequently executed in the context of other users' browser sessions. Exploitation requires some user interaction (viewing the malicious content) but does not require administrative privileges. Patches have been released for the affected versions (e.g., WebTop 6.8 P18, Administrator 7.2 P18).
Affected products
- EMC Documentum WebTop 6.8 prior to P18, 6.8.1 prior to P06
- EMC Documentum TaskSpace 6.7SP3 prior to P02
- EMC Documentum Capital Projects 1.9 prior to P30, 1.10 prior to P17
- EMC Documentum Administrator 7.0, 7.1, 7.2 prior to P18
Timeline
- 2017-01-23: advisory: Initial NVD publication