CVE-2014-2508
Summary
| CVE | CVE-2014-2508 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-08 04:31:53 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on database actions via vectors involving DQL hints. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:C/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Documentum Content Server | 6.0 | All | All | All |
| Application | Emc | Documentum Content Server | 6.5 | All | All | All |
| Application | Emc | Documentum Content Server | 6.5 | sp1 | All | All |
| Application | Emc | Documentum Content Server | 6.5 | sp2 | All | All |
| Application | Emc | Documentum Content Server | 6.5 | sp3 | All | All |
| Application | Emc | Documentum Content Server | 6.6 | All | All | All |
| Application | Emc | Documentum Content Server | 6.7 | - | All | All |
| Application | Emc | Documentum Content Server | 6.7 | sp2 | All | All |
| Application | Emc | Documentum Content Server | 7.0 | All | All | All |
| Application | Emc | Documentum Content Server | 7.1 | All | All | All |
| Application | Emc | Documentum Content Server | All | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC Documentum Content Server Escalation / Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| EMC Documentum Content Server Flaws Let Remote Authenticated Users Gain Elevated Privileges and Inject DQL Commands - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA58954 - EMC Documentum Content Server Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| EMC Documentum Content Server CVE-2014-2508 Remote Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/bugtraq/2014-06/0051.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.