Lucene search

K
cve[email protected]CVE-2014-2511
HistoryAug 20, 2014 - 11:17 a.m.

CVE-2014-2511

2014-08-2011:17:13
CWE-79
web.nvd.nist.gov
22
cve-2014-2511
emc documentum
webtop
xss
vulnerabilities
remote attackers
web script
html
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.6%

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.

Affected configurations

NVD
Node
emcdigital_assets_managerMatch6.5
OR
emcdigital_assets_managerMatch6.5sp5
OR
emcdigital_assets_managerMatch6.5sp6
OR
emcdocumentum_administratorMatch6.7
OR
emcdocumentum_administratorMatch6.7sp1
OR
emcdocumentum_administratorMatch6.7sp2
OR
emcdocumentum_administratorMatch7.0
OR
emcdocumentum_administratorMatch7.1
OR
emcdocumentum_capital_projectsMatch1.8
OR
emcdocumentum_capital_projectsMatch1.9
OR
emcdocumentum_webtopMatch6.7
OR
emcdocumentum_webtopMatch6.7sp1
OR
emcdocumentum_webtopMatch6.7sp2
OR
emcengineering_plant_facilities_management_solution_for_documentumMatch1.7
OR
emcengineering_plant_facilities_management_solution_for_documentumMatch1.7sp1
OR
emcrecords_clientMatch6.7
OR
emcrecords_clientMatch6.7sp1
OR
emcrecords_clientMatch6.7sp2
OR
emctask_spaceMatch6.7
OR
emctask_spaceMatch6.7sp1
OR
emctask_spaceMatch6.7sp2
OR
emcweb_publishersMatch6.5
OR
emcweb_publishersMatch6.5sp6
OR
emcweb_publishersMatch6.5sp7

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.6%

Related for CVE-2014-2511