Lucene search

K
cveDellCVE-2014-2512
HistoryJul 01, 2014 - 12:55 a.m.

CVE-2014-2512

2014-07-0100:55:05
CWE-79
dell
web.nvd.nist.gov
31
cve-2014-2512
xss
emc documentum
eroom
7.4.3
security vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

50.2%

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

Nvd
Node
emcdocumentum_eroomMatch7.4.3
OR
emcdocumentum_eroomMatch7.4.4
OR
emcdocumentum_eroomMatch7.4.4sp1
VendorProductVersionCPE
emcdocumentum_eroom7.4.3cpe:2.3:a:emc:documentum_eroom:7.4.3:*:*:*:*:*:*:*
emcdocumentum_eroom7.4.4cpe:2.3:a:emc:documentum_eroom:7.4.4:*:*:*:*:*:*:*
emcdocumentum_eroom7.4.4cpe:2.3:a:emc:documentum_eroom:7.4.4:sp1:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

50.2%