CVE-2015-0540
Summary
| CVE | CVE-2015-0540 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-25 19:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | SQL injection vulnerability in the xAdmin interface in EMC Document Sciences xPression 4.2 before P44 and 4.5 SP1 before P03 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Document Sciences Xpression | 4.2 | - | - | All |
| Application | Emc | Document Sciences Xpression | 4.2 | - | - | All |
| Application | Emc | Document Sciences Xpression | 4.2 | - | - | All |
| Application | Emc | Document Sciences Xpression | 4.5 | sp1 | All | All |
| Application | Emc | Document Sciences Xpression | 4.5 | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bugtraq: ESA-2015-087 EMC Document Sciences xPression SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.