CVE-2014-2520 PUBLISHED CVSS 6.300000190734863 MEDIUM

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request.

EPSS 0.42% · 61.8th percentile

Risk Scores

CVSS v2.0
6.300000190734863
EPSS Score
0.42%
61.8th percentile

Affected Products

VendorProductVersions
emcdocumentum_content_server7.1, 0, 6.0
n/an/an/a

Timeline

References

Open in Interactive Console →