Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02, when debug_trace is configured, allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket.
| Software | From | Fixed in |
|---|---|---|
| emc / documentum_content_server | 6.7-sp2 | 6.7-sp2.x |
| emc / documentum_content_server | 7.0 | 7.0.x |
| emc / documentum_content_server | 7.2 | 7.2.x |
| emc / documentum_content_server | 7.1 | 7.1.x |
| emc / documentum_content_server | 6.7-sp1 | 6.7-sp1.x |