{"api_version":"1","generated_at":"2026-07-23T21:09:40+00:00","cve":"CVE-2014-2507","urls":{"html":"https://cve.report/CVE-2014-2507","api":"https://cve.report/api/cve/CVE-2014-2507.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2507","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2507"},"summary":{"title":"CVE-2014-2507","description":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to unspecified methods.","state":"PUBLISHED","assigner":"dell","published_at":"2014-06-08 04:31:53","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-78","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html","name":"http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server Escalation / Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030339","name":"http://www.securitytracker.com/id/1030339","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server Flaws Let Remote Authenticated Users Gain Elevated Privileges and Inject DQL Commands - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/67916","name":"http://www.securityfocus.com/bid/67916","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/532596/100/0/threaded","name":"http://www.securityfocus.com/archive/1/532596/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/58954","name":"http://secunia.com/advisories/58954","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA58954 - EMC Documentum Content Server Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2507","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2507","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.7","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.7","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2507","vulnerable":"1","versionEndIncluding":"6.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"*","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:14:26.769Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20140605 ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html"},{"name":"67916","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/67916"},{"name":"1030339","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030339"},{"name":"20140630 ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/532596/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html"},{"name":"58954","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/58954"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-06-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to unspecified methods."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"20140605 ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html"},{"name":"67916","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/67916"},{"name":"1030339","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030339"},{"name":"20140630 ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/532596/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html"},{"name":"58954","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/58954"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2014-2507","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to unspecified methods."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20140605 ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2014-06/0051.html"},{"name":"67916","refsource":"BID","url":"http://www.securityfocus.com/bid/67916"},{"name":"1030339","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030339"},{"name":"20140630 ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/532596/100/0/threaded"},{"name":"http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/126960/EMC-Documentum-Content-Server-Escalation-Injection.html"},{"name":"58954","refsource":"SECUNIA","url":"http://secunia.com/advisories/58954"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2014-2507","datePublished":"2014-06-08T01:00:00.000Z","dateReserved":"2014-03-14T00:00:00.000Z","dateUpdated":"2024-08-06T10:14:26.769Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-06-08 04:31:53","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-78","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:*:sp1:*:*:*:*:*:*","versionEndIncluding":"6.7","matchCriteriaId":"7B188672-1EC2-4338-A868-BD562962D356"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"FDBAEC8D-D945-48CA-84DD-EDBE8029F636"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:*:*:*:*:*:*:*","matchCriteriaId":"730510E9-1AE8-44BF-A1DE-5ED40F22D0B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:sp1:*:*:*:*:*:*","matchCriteriaId":"CC8840D2-5DE8-4EB6-A03F-BFF1C8A9BF1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:sp2:*:*:*:*:*:*","matchCriteriaId":"3AC51C95-97DC-44B4-9935-9423CE60289A"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:sp3:*:*:*:*:*:*","matchCriteriaId":"0ACB8EDE-C6AF-4B85-83ED-74097A206B49"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.6:*:*:*:*:*:*:*","matchCriteriaId":"25CD1EE0-4E72-4C42-857B-AA45F0A17BBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*","matchCriteriaId":"49659818-958F-4B5E-8DA4-B592C67DD13F"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:*","matchCriteriaId":"B4E00544-98F6-439C-8F4D-822FCAE775CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"8335062A-5A8E-4076-B351-7DFA19CEC818"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*","matchCriteriaId":"B283F797-6DAA-40E1-9FAB-16FCAA5241B4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2507","Ordinal":"1","Title":"CVE-2014-2507","CVE":"CVE-2014-2507","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2507","Ordinal":"1","NoteData":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to unspecified methods.","Type":"Description","Title":"CVE-2014-2507"},{"CveYear":"2014","CveId":"2507","Ordinal":"2","NoteData":"2014-06-07","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2507","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}