6.3
CVSSv2

CVE-2014-2520

Published: 20/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.3 | Impact Score: 6.9 | Exploitability Score: 6.8
VMScore: 561
Vector: AV:N/AC:M/Au:S/C:C/I:N/A:N

Vulnerability Summary

EMC Documentum Content Server prior to 6.7 SP2 P16 and 7.x prior to 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

emc documentum content server 7.0

emc documentum content server 7.1

emc documentum content server

emc documentum content server 6.5

emc documentum content server 6.7

emc documentum content server 6.0

emc documentum content server 6.6

Exploits

OpenText Documentum Content Server version 73 suffers from a remote SQL injection vulnerability due to a previously announced fix being incomplete ...