Get the real story via our monthly newsletter

Search

    2
    0

rss

Send to a colleague

Home > Commentary > Trends Archive > Documentum Fixes Security Flaw

Browse TrendWatch Blog

Recent Blog Entries

The Complete Archive

Trends by Vendor


TrendWatch by Channel

Web Content Management Trends

Enterprise Portals Trends

ECM Trends

Web Analytics Trends

Enterprise Search Trends

SharePoint Trends

Digital & Media Asset Management Trends

XML & Component Content Management Trends


Report Excerpt

The ECM Suites Report 2008 looks at... Vignette's ECM Suite

"With its focus on content consumption, Vignette has differentiated itself from other ECM vendors by promoting its portal as the meeting ground for content across formats and repositories. The cost-effective portal and easily deployed records and document management module are among the platform's best features, but the vendor has yet to smooth over disparate infrastructure requirements and fully stabilize its complex VCM environment ..."

(p. 229)

More about The ECM Suites Report 2008

 

TrendWatch Blog

Documentum Fixes Security Flaw

06-Feb-2008

Yesterday, security analysis firm CYBSEC S.A. released an advisory describing a vulnerability in Documentum 5.3 that, if uncorrected, would "allow an attacker to overwrite arbitrary files on the server filesystem." The vulnerability reportedly affects Documentum Administrator Version 5.3.0.313 and Documentum Webtop version 5.3.0.317. CYBSEC said other applications and versions may also be affected.

EMC Corporation's Documentum division was notified of the situation on December 17, 2007 and responded to CYBSEC the same day. CYBSEC says it supplied EMC with a "fully functional exploit" for analysis.

Documentum confirmed on January 4 that the fix was in SP4. If you are like most EMC customers and still running Documentum 5.3 (the latest is D6, released in August 2007), you should check to make sure your system is up-to-date with respect to service packs.

Indeed, whatever tool you deploy, keeping up with service packs with the same surety that you track patches to your operating system(s) is essential.

- Submitted by: Kas Thomas, Analyst

All ECM Channel Trends

Join the conversation

Digg This! Search Technorati Tag it on Del.icio.us



Get a Free Sample

Wondering about CMS Watch research? Sign up to receive free samples of any of our products.




What we do

CMS Watch™ evaluates content-oriented technologies, publishing head-to-head comparative reviews of leading solutions. What makes us special?

  • Our critical analysis exposes product weaknesses as well as strengths
  • We deliver unrivaled technical depth and comprehensive project advice
  • Our research is led by international topic experts
  • We only work for buyers -- never for vendors

Contact us

CMS Watch

info@cmswatch.com

18113 Town Center Drive, Ste 217

Olney, MD USA 20832

1 800 325 6190 (N. America only)

+1 617 763 5336 (customer service)

+1 301 585 7004 (editorial)

Fax: +1 214 242 3048