← Back

CVE-2014-4626

nvd nist
Published: Dec 17, 2014Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515.

Affected (5)

1 product
Documentum Content Server
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Emc
Up to 6.7
Version 6.7
Version 6.7 sp2
Version 7.0
Version 7.1

Related CWEs

References (8)

Source: security_alert@emc.com
Third Party AdvisoryUS Government Resource
Source: security_alert@emc.com
Third Party AdvisoryUS Government Resource
Source: security_alert@emc.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.