Delivering fearless advice since 2001. Here's our story
What Real Independence means. Find Out
Kas Thomas
6-Feb-2008
Tags: Document Management (ECM), Web Content and Experience Management, , Documentum Web Content Management
Yesterday, security analysis firm CYBSEC S.A. released an advisory describing a vulnerability in Documentum 5.3 that, if uncorrected, would "allow an attacker to overwrite arbitrary files on the server filesystem." The vulnerability reportedly affects Documentum Administrator Version 5.3.0.313 and Documentum Webtop version 5.3.0.317. CYBSEC said other applications and versions may also be affected.
EMC Corporation's Documentum division was notified of the situation on December 17, 2007 and responded to CYBSEC the same day. CYBSEC says it supplied EMC with a "fully functional exploit" for analysis.
Documentum confirmed on January 4 that the fix was in SP4. If you are like most EMC customers and still running Documentum 5.3 (the latest is D6, released in August 2007), you should check to make sure your system is up-to-date with respect to service packs.
Indeed, whatever tool you deploy, keeping up with service packs with the same surety that you track patches to your operating system(s) is essential.
Get the Real Story bi-weekly.
USA & Canada
+1 800 325 6190
UK
+44 (0) 20 3318 1911
International
+1 617 340 6464
All Other Inquiries
"The Search & Information Access Research is jammed full of great stuff..."
Lou Rosenfeld, Leading independent information architecture guru
Copyright Real Story Group 2001 - 2012. All rights reserved.
All analyst firms claim to be independent or vendor-neutral. We're different.
Get the real story on commercial and open source tools from a firm that works only for you, the technology customer.
Thank you for signing up for The Real Story Group Newsletter. You will receive our monthly newsletter, plus updates with new information on the technology streams you have expressed interest in below.