← Back

Documentum Xcp

documentum_xcp

Vendor: Emc • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emc
1Documentum Xcp
May 6, 2026
Mar 9, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
EMC Documentum xCP 2.1 before patch 24 and 2.2 before patch 12 allows remote authenticated users to obtain sensitive user-account metadata via a members/xcp_member API call.
1Emc
1Documentum Xcp
May 6, 2026
Feb 12, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity refe...Show more
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Emc
1Documentum Xcp
May 6, 2026
Feb 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a que...Show more
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request.Show less