CVE-2014-2520
6.3
Vector
AV:N/AC:M/Au:S/C:C/I:N/A:N
Exploitability: 6.8 / Impact: 6.9
Source: NVD
Description
EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request.
Affected (11)
Products: Emc: Documentum Content Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.7 |
Related CWEs
References (10)
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.