CVE-2014-2506
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
08/06/2014
Last modified:
12/04/2025
Description
EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors.
Impact
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:emc:documentum_content_server:*:sp1:*:*:*:*:*:* | 6.7 (including) | |
| cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.5:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.5:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.5:sp3:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html
- http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html
- http://secunia.com/advisories/58954
- http://www.securityfocus.com/archive/1/532596/100/0/threaded
- http://www.securityfocus.com/bid/67917
- http://www.securitytracker.com/id/1030339
- http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html
- http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html
- http://secunia.com/advisories/58954
- http://www.securityfocus.com/archive/1/532596/100/0/threaded
- http://www.securityfocus.com/bid/67917
- http://www.securitytracker.com/id/1030339



