CVE-2016-0882

MEDIUM

EMC Documentum xCP <2.1-2.2 - Info Disclosure

Title source: llm

Description

EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Scores

CVSS v3 5.4
EPSS 0.0048
EPSS Percentile 64.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Classification

Status draft

Affected Products (2)

emc/documentum_xcp
emc/documentum_xcp

Timeline

Published Feb 12, 2016
Tracked Since Feb 18, 2026