CVE-2014-4626 PUBLISHED CVSS 9 CRITICAL

EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515.

EPSS 1.20% · 78.8th percentile

Risk Scores

CVSS v2.0
9
EPSS Score
1.20%
78.8th percentile

Affected Products

VendorProductVersions
n/an/an/a
emcdocumentum_content_server0, 6.7, 6.7

Timeline

References

Open in Interactive Console →