{"api_version":"1","generated_at":"2026-07-23T12:25:10+00:00","cve":"CVE-2014-4621","urls":{"html":"https://cve.report/CVE-2014-4621","api":"https://cve.report/api/cve/CVE-2014-4621.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-4621","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-4621"},"summary":{"title":"CVE-2014-4621","description":"EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors.","state":"PUBLISHED","assigner":"dell","published_at":"2014-09-17 10:55:07","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id/1030855","name":"http://www.securitytracker.com/id/1030855","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server Flaws Let Remote Authenticated Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95989","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95989","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/61251","name":"http://secunia.com/advisories/61251","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA61251 - EMC Documentum Content Server Two Security Bypass Security Issues - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html","name":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/69817","name":"http://www.securityfocus.com/bid/69817","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC Documentum Content Server CVE-2014-4621 Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-4621","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-4621","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.5","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.7","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"6.7","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"4621","vulnerable":"1","versionEndIncluding":"6.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_content_server","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:20:26.948Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"61251","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/61251"},{"name":"20140915 ESA-2014-091: EMC Documentum Content Server Multiple Privilege Escalation Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html"},{"name":"emc-documentum-cve20144621-priv-esc(95989)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95989"},{"name":"69817","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69817"},{"name":"1030855","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030855"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-09-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"61251","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/61251"},{"name":"20140915 ESA-2014-091: EMC Documentum Content Server Multiple Privilege Escalation Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html"},{"name":"emc-documentum-cve20144621-priv-esc(95989)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95989"},{"name":"69817","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69817"},{"name":"1030855","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030855"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2014-4621","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"61251","refsource":"SECUNIA","url":"http://secunia.com/advisories/61251"},{"name":"20140915 ESA-2014-091: EMC Documentum Content Server Multiple Privilege Escalation Vulnerabilities","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html"},{"name":"emc-documentum-cve20144621-priv-esc(95989)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95989"},{"name":"69817","refsource":"BID","url":"http://www.securityfocus.com/bid/69817"},{"name":"1030855","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030855"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2014-4621","datePublished":"2014-09-17T10:00:00.000Z","dateReserved":"2014-06-24T00:00:00.000Z","dateUpdated":"2024-08-06T11:20:26.948Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-09-17 10:55:07","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:*:sp2:*:*:*:*:*:*","versionEndIncluding":"6.7","matchCriteriaId":"D76BC7EC-B77D-4C40-AC45-347EC6618C94"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"FDBAEC8D-D945-48CA-84DD-EDBE8029F636"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:*:*:*:*:*:*:*","matchCriteriaId":"730510E9-1AE8-44BF-A1DE-5ED40F22D0B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:sp1:*:*:*:*:*:*","matchCriteriaId":"CC8840D2-5DE8-4EB6-A03F-BFF1C8A9BF1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:sp2:*:*:*:*:*:*","matchCriteriaId":"3AC51C95-97DC-44B4-9935-9423CE60289A"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.5:sp3:*:*:*:*:*:*","matchCriteriaId":"0ACB8EDE-C6AF-4B85-83ED-74097A206B49"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.6:*:*:*:*:*:*:*","matchCriteriaId":"25CD1EE0-4E72-4C42-857B-AA45F0A17BBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*","matchCriteriaId":"49659818-958F-4B5E-8DA4-B592C67DD13F"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:6.7:sp1:*:*:*:*:*:*","matchCriteriaId":"414C33C7-CD76-49A4-9BE5-354860F2F635"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"8335062A-5A8E-4076-B351-7DFA19CEC818"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*","matchCriteriaId":"B283F797-6DAA-40E1-9FAB-16FCAA5241B4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"4621","Ordinal":"1","Title":"CVE-2014-4621","CVE":"CVE-2014-4621","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"4621","Ordinal":"1","NoteData":"EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors.","Type":"Description","Title":"CVE-2014-4621"},{"CveYear":"2014","CveId":"4621","Ordinal":"2","NoteData":"2014-09-17","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"4621","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}