CVE-2014-4639

EMC Documentum WDK <6.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, which makes it easier for remote attackers to conduct phishing attacks via brute-force attempts to predict the parameter value.

References (4)

Core 4
Core References
Broken Link mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2015-01/0009.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031497
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99636

Scores

EPSS 0.0035
EPSS Percentile 57.4%

Details

CWE
CWE-189
Status published
Products (1)
emc/documentum_wdk < 6.7
Published Jan 07, 2015
Tracked Since Feb 18, 2026