CVE-2016-0882
EUVD-2016-089312.02.2016, 01:59
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| emc | documentum_xcp | 2.1 |
| emc | documentum_xcp | 2.2 |
𝑥
= Vulnerable software versions