CVE-2014-2520
Summary
| CVE | CVE-2014-2520 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-20 11:17:13 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Documentum Content Server | 6.0 | All | All | All |
| Application | Emc | Documentum Content Server | 6.5 | All | All | All |
| Application | Emc | Documentum Content Server | 6.5 | sp1 | All | All |
| Application | Emc | Documentum Content Server | 6.5 | sp2 | All | All |
| Application | Emc | Documentum Content Server | 6.5 | sp3 | All | All |
| Application | Emc | Documentum Content Server | 6.6 | All | All | All |
| Application | Emc | Documentum Content Server | 6.7 | - | All | All |
| Application | Emc | Documentum Content Server | 6.7 | sp1 | All | All |
| Application | Emc | Documentum Content Server | 7.0 | All | All | All |
| Application | Emc | Documentum Content Server | 7.1 | All | All | All |
| Application | Emc | Documentum Content Server | All | sp2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC Documentum Content Server Bug Lets Remote Authenticated Users Inject DQL Commands, Execute Arbitrary Code, and Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Advisory SA60571 - EMC Documentum Content Server Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| EMC Documentum Content Server CVE-2014-2520 Documentum Query Language Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.