{"api_version":"1","generated_at":"2026-07-23T07:15:33+00:00","cve":"CVE-2014-2513","urls":{"html":"https://cve.report/CVE-2014-2513","api":"https://cve.report/api/cve/CVE-2014-2513.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2513","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2513"},"summary":{"title":"CVE-2014-2513","description":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script.","state":"PUBLISHED","assigner":"dell","published_at":"2014-07-08 11:06:01","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.2","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:P","baseScore":8.2,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/68435","name":"http://www.securityfocus.com/bid/68435","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server CVE-2014-2513 Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-07/0024.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-07/0024.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030529","name":"http://www.securitytracker.com/id/1030529","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server Flaws Let Remote Authenticated Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/59757","name":"http://secunia.com/advisories/59757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA59757 - EMC Documentum Content Server Two Security Bypass Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2513","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2513","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2513","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.7","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2513","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.7","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2513","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2513","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2513","vulnerable":"1","versionEndIncluding":"6.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"*","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:14:26.548Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1030529","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030529"},{"name":"59757","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59757"},{"name":"20140707 ESA-2014-064: EMC Documentum Content Server Privilege Escalation Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-07/0024.html"},{"name":"68435","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/68435"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-07-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-01-05T14:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"1030529","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030529"},{"name":"59757","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59757"},{"name":"20140707 ESA-2014-064: EMC Documentum Content Server Privilege Escalation Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-07/0024.html"},{"name":"68435","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/68435"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2014-2513","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1030529","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030529"},{"name":"59757","refsource":"SECUNIA","url":"http://secunia.com/advisories/59757"},{"name":"20140707 ESA-2014-064: EMC Documentum Content Server Privilege Escalation Vulnerabilities","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2014-07/0024.html"},{"name":"68435","refsource":"BID","url":"http://www.securityfocus.com/bid/68435"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2014-2513","datePublished":"2014-07-08T10:00:00.000Z","dateReserved":"2014-03-14T00:00:00.000Z","dateUpdated":"2024-08-06T10:14:26.548Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-08 11:06:01","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:P","baseScore":8.2,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":9.5,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:*:sp1:*:*:*:*:*:*","versionEndIncluding":"6.7","matchCriteriaId":"7B188672-1EC2-4338-A868-BD562962D356"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*","matchCriteriaId":"49659818-958F-4B5E-8DA4-B592C67DD13F"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:*","matchCriteriaId":"B4E00544-98F6-439C-8F4D-822FCAE775CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"8335062A-5A8E-4076-B351-7DFA19CEC818"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*","matchCriteriaId":"B283F797-6DAA-40E1-9FAB-16FCAA5241B4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2513","Ordinal":"1","Title":"CVE-2014-2513","CVE":"CVE-2014-2513","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2513","Ordinal":"1","NoteData":"EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script.","Type":"Description","Title":"CVE-2014-2513"},{"CveYear":"2014","CveId":"2513","Ordinal":"2","NoteData":"2014-07-08","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2513","Ordinal":"3","NoteData":"2017-01-05","Type":"Other","Title":"Modified"}]}}}