Documentum Eroom

Vendor:

First CVE: Jul 19, 2011 · Active for 15 years

7
Total CVEs
More Total CVEs than 85% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Documentum Eroom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2011
15 years ago
Most Recent CVE
Feb 3, 2017
3,462 days ago

CVE Severity & Scoring

Documentum Eroom7 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (14.3%)
Unknown6 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (14.3%)
High0 (0.0%)
Unknown6 (85.7%)
User Interaction
None1 (14.3%)
Unknown6 (85.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (14.3%)
Unknown6 (85.7%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other produc
Jul 19, 201110.031NONO
The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allo
Nov 9, 20118.526NONO
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 include
Feb 3, 20179.824NONO
EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors.
Mar 15, 20127.523NONO
Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Mar 15, 20124.317NONO
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script o
Jul 1, 20143.516NONO
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
Nov 6, 20134.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Documentum Eroom

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.5.019.81.6%00
7.4.519.81.6%00
7.4.426.71.6%00
7.4.346.63.4%00
7.4.256.92.8%00
7.4.156.92.8%00
7.4.014.30.9%00
7.3.046.21.5%00