CVE-2016-9873
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
03/02/2017
Last modified:
20/04/2025
Description
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt services by causing execution of arbitrary DQL commands on the application.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:emc:documentum_d2:4.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:emc:documentum_d2:4.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page