CVE-2016-0882
MEDIUMEMC Documentum xCP <2.1-2.2 - Info Disclosure
Title source: llmDescription
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Scores
CVSS v3
5.4
EPSS
0.0048
EPSS Percentile
64.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Classification
Status
draft
Affected Products (2)
emc/documentum_xcp
emc/documentum_xcp
Timeline
Published
Feb 12, 2016
Tracked Since
Feb 18, 2026