ESA-2012-009 – Security Alert on EMC Documentum: security patch ready

Today I verified that the security issue reported on this site and on many security related sites like SecurityFocus affects even Content Server 5.3 in addition to many 6.x systems.

I know the exploit and I think you have to upgrade or install patches if:

  1. your system are using one of the servers reported below:
      • Content Server 5.3
      • Content Server 6.0
      • Content Server 6.0 SP1
      • Content Server 6.5
      • Content Server 6.5 SP1
      • Content Server6.5 SP2 P01
      • Content Server6.5 SP3 P01
      •  Content Server6.6 SP2 P01
  2. there are active users with just Sysadmin privilege defined into the repository.

EMC did not release any patches for this security issue: EMC just strongly recommends content server upgrade to one of these servers:

  • Content Server 6.5 SP2 P02 or later
  • Content Server 6.5 SP3 P02 or later
  • Content Server 6.6 P02 or later
  • Content Server 6.7

If you cannot upgrade or if you do not want to upgrade your systems right now, I can help you: I created a patch that solve this security issue. Send an email to yuri.simione@artika.biz for more info about that.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

ESA-2012-009: EMC Documentum Content Server privilege elevation vulnerability.

EMC Identifier: ESA-2012-009

EMC Identifier: CS-16072

EMC Identifier: CS-16073

CVE Identifier: CVE-2011-4144

Severity Rating: CVSS v2 Base Score: 6.8 (AV:L/AC:L/Au:S/C:C/I:C/A:C)

Affected prodcuts:

EMC Documentum Content Server 6.0

EMC Documentum Content Server 6.5

EMC Documentum Content Server 6.6

Vulnerability Summary:

EMC Documentum Content Server contains a privilege elevation vulnerability that may allow an unauthorized user to obtain highest administrative privileges on the system.

Vulnerability Details:

EMC Documentum Content Server contains a security vulnerability that may allow a system administrator to elevate their or other users? privileges to highest super user privileges without appropriate authorization. Refer to EMC Documentum Content Server documentation for information on Documentum Content Server user and group privileges.

Resolution:

The following EMC Documentum Content Serve products contain resolutions to this issue:

EMC Documentum Content Server 6.5 SP2 P02 and later

EMC Documentum Content Server 6.5 SP3 P02 and later

EMC Documentum Content Server 6.6 P02 and later

EMC strongly recommends all customers upgrade or install identified patches at the earliest opportunity.

Notes: EMC Documentum Content Server 6.7 and later is not affected by this issue.

Link to remedies:

Registered EMC Powerlink customers can download software from Powerlink: https://emc.subscribenet.com/control/dctm/product?plneID=3895. Download the appropriate version for your needs. Instructions for application and installation are included in the software download readme files or patch release notes.

Credits:

EMC would like to thank Yuri Simione for reporting this issue.

Because the view is restricted based on customer agreements, you may not have permission to view certain downloads. Should you not see a software download you believe you should have access to, follow the instructions in EMC Knowledgebase solution emc116045.

Notes: For an explanation of Severity Ratings, refer to EMC Knowledgebase solution emc218831. EMC recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.

Notes: EMC Corporation distributes EMC Security Advisories in order to bring to the attention of users of the affected EMC products important security information. EMC recommends all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. EMC disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall EMC or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if EMC or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

EMC Product Security Response Center

Security_Alert (at) EMC (dot) com [email concealed]

http://www.emc.com/contact-us/contact/product-security-response-center.h
tm

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Cygwin)

iEYEARECAAYFAk8pXeEACgkQtjd2rKp+ALw9YQCfSw618BaZVpoKPzDB6suTV7sQ
MmQAoMM53n9+Gd4NLlSiIivnZELGGAq5
=W/8g
-----END PGP SIGNATURE-----

Follow me on Linkedin  or on Twitter

This entry was posted in ECM, EMC, Frontpage, Security alert and tagged , , , , , , , . Bookmark the permalink.

Leave a Reply