Vulnerability CVE-2014-4622


Published: 2014-09-17

Description:
EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended restrictions on data access and server actions, via unspecified vectors.

CVSS2 => (AV:N/AC:H/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.1/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Remote
High
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
EMC -> Documentum content server 

 References:
http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html
http://secunia.com/advisories/61251
http://www.securityfocus.com/bid/69819
http://www.securitytracker.com/id/1030855
http://xforce.iss.net/xforce/xfdb/95990

Copyright 2024, cxsecurity.com

 

Back to Top