CVE-2017-4976: Emc Esrs Policy Manager

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may login to the system and gain administrator privileges to the local LDAP directory server.

Affected products

  • Emc Esrs Policy Manager: up to and including 6.7

Published 2017-07-09. Last modified 2026-06-17.