CVE-2014-2503
Summary
| CVE | CVE-2014-2503 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-06 00:55:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on querying objects via a crafted parameter in a query string. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Documentum Digital Asset Manager | 6.5 | sp3 | All | All |
| Application | Emc | Documentum Digital Asset Manager | 6.5 | sp4 | All | All |
| Application | Emc | Documentum Digital Asset Manager | 6.5 | sp5 | All | All |
| Application | Emc | Documentum Digital Asset Manager | 6.5 | sp6 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| archives.neohapsis.com/archives/bugtraq/2014-06/0037.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| EMC Documentum Digital Asset Manager Blind DQL Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| EMC Documentum Digital Asset Manager Input Validation Flaw Lets Remote Users Inject DQL Commands - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.