Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3281


Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.


Published

2013-11-06T15:55:05.093

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emc documentum_taskspace ≤ 6.7 Yes
Application emc documentum_taskspace 6.7 Yes
Application emc documentum_taskspace 6.7 Yes
Application emc documentum_capital_projects ≤ 1.8 Yes
Application emc documentum_wdk ≤ 6.7 Yes
Application emc documentum_wdk 6.7 Yes
Application emc documentum_wdk 6.7 Yes
Application emc documentum_digital_asset_manager ≤ 6.5 Yes
Application emc documentum_digital_asset_manager 6.5 Yes
Application emc documentum_digital_asset_manager 6.5 Yes
Application emc documentum_digital_asset_manager 6.5 Yes
Application emc documentum_digital_asset_manager 6.5 Yes
Application emc documentum_digital_asset_manager 6.5 Yes
Application emc documentum_administrator ≤ 6.7 Yes
Application emc documentum_administrator 6.7 Yes
Application emc documentum_administrator 6.7 Yes
Application emc documentum_webtop ≤ 6.7 Yes
Application emc documentum_webtop 6.7 Yes
Application emc documentum_webtop 6.7 Yes
Application emc documentum_web_publisher ≤ 6.5 Yes
Application emc documentum_web_publisher 6.5 Yes
Application emc documentum_web_publisher 6.5 Yes
Application emc documentum_web_publisher 6.5 Yes
Application emc documentum_web_publisher 6.5 Yes
Application emc documentum_web_publisher 6.5 Yes
Application emc documentum_web_publisher 6.5 Yes

References