Lucene search

K
cveDellCVE-2014-2513
HistoryJul 08, 2014 - 11:06 a.m.

CVE-2014-2513

2014-07-0811:06:01
CWE-20
dell
web.nvd.nist.gov
43
emc documentum
content server
cve-2014-2513
privilege escalation
security vulnerability

CVSS2

8.2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:C/I:C/A:P

AI Score

8.6

Confidence

High

EPSS

0.009

Percentile

82.9%

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script.

Affected configurations

Nvd
Node
emcdocumentum_content_serverRange6.7sp1
OR
emcdocumentum_content_serverMatch6.7-
OR
emcdocumentum_content_serverMatch6.7sp2
OR
emcdocumentum_content_serverMatch7.0
OR
emcdocumentum_content_serverMatch7.1
VendorProductVersionCPE
emcdocumentum_content_server*cpe:2.3:a:emc:documentum_content_server:*:sp1:*:*:*:*:*:*
emcdocumentum_content_server6.7cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*
emcdocumentum_content_server6.7cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:*
emcdocumentum_content_server7.0cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*
emcdocumentum_content_server7.1cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*

CVSS2

8.2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:C/I:C/A:P

AI Score

8.6

Confidence

High

EPSS

0.009

Percentile

82.9%