Vignette Content Management Security Update
Summary
We have identified a vulnerability in Vignette Content Management, which in exceptional circumstances could allow a low privileged user to escalate their privileges and gain application administrator access to Vignette Content Management. The level of access gained would allow the user to create, approve and publish content as well as change application configurations.
A fix is available now in KB 9872. Vignette recommends that you apply the fix if you have an affected version of Vignette Content Management.
Recommendation
Vignette recommends that customers apply the update immediately.
Affected Versions
Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, 7.5 and all associated service packs.
Fix
A fix is available as an independent software update or as a cumulative software update for VCM versions 7.3.1 to 7.5. You can find additional information and download the update now from KB 9872.
Vignette is working on the fix for VCM 7.3.0.5 and will notify customers when it is available.
Support
If you have any questions, please log in to Vignette Connect and submit a VOLSS ticket or contact Customer Care at customercare@vignette.com.
Sincerely,
Ken Skinner
VP, Worldwide Customer Care
Vignette Corporation
|