{"api_version":"1","generated_at":"2026-07-23T10:50:27+00:00","cve":"CVE-2015-0518","urls":{"html":"https://cve.report/CVE-2015-0518","api":"https://cve.report/api/cve/CVE-2015-0518.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-0518","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-0518"},"summary":{"title":"CVE-2015-0518","description":"The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to obtain superuser privileges via an unspecified method call that modifies group permissions.","state":"PUBLISHED","assigner":"dell","published_at":"2015-02-14 15:59:01","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id/1031693","name":"http://www.securitytracker.com/id/1031693","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"EMC Documentum D2 Bugs Lets Remote Authenticated Users Obtain Sensitive Information and Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/100875","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/100875","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/72502","name":"http://www.securityfocus.com/bid/72502","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"EMC Documentum D2 CVE-2015-0518 Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.html","name":"http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-0518","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0518","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"518","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_d2","cpe6":"3.1","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"518","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_d2","cpe6":"3.1","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"518","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_d2","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"518","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_d2","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"518","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"documentum_d2","cpe6":"4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:10:11.051Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1031693","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031693"},{"name":"emc-documentum-cve20150518-priv-esc(100875)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/100875"},{"name":"72502","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/72502"},{"name":"20150204 ESA-2015-010: EMC Documentum D2 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-02-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to obtain superuser privileges via an unspecified method call that modifies group permissions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"1031693","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031693"},{"name":"emc-documentum-cve20150518-priv-esc(100875)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/100875"},{"name":"72502","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/72502"},{"name":"20150204 ESA-2015-010: EMC Documentum D2 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2015-0518","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to obtain superuser privileges via an unspecified method call that modifies group permissions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1031693","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031693"},{"name":"emc-documentum-cve20150518-priv-esc(100875)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/100875"},{"name":"72502","refsource":"BID","url":"http://www.securityfocus.com/bid/72502"},{"name":"20150204 ESA-2015-010: EMC Documentum D2 Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2015-02/0031.html"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2015-0518","datePublished":"2015-02-14T15:00:00.000Z","dateReserved":"2014-12-17T00:00:00.000Z","dateUpdated":"2024-08-06T04:10:11.051Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-02-14 15:59:01","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_d2:3.1:-:*:*:*:*:*:*","matchCriteriaId":"9FE3ABC6-7F44-436A-B78A-C7FC6310C1FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_d2:3.1:sp1:*:*:*:*:*:*","matchCriteriaId":"BEECDCAB-54A9-4A99-B77E-6DAD0513AA3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_d2:4.0:*:*:*:*:*:*:*","matchCriteriaId":"4A265F6B-0975-4CA2-832D-AF0FA38B0077"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_d2:4.1:*:*:*:*:*:*:*","matchCriteriaId":"F39C8470-59DA-4759-A8B4-2DEE6DCAAE1A"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:documentum_d2:4.2:*:*:*:*:*:*:*","matchCriteriaId":"BC69558D-8121-4CA9-BABB-9ACF77808706"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"518","Ordinal":"1","Title":"CVE-2015-0518","CVE":"CVE-2015-0518","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"518","Ordinal":"1","NoteData":"The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to obtain superuser privileges via an unspecified method call that modifies group permissions.","Type":"Description","Title":"CVE-2015-0518"},{"CveYear":"2015","CveId":"518","Ordinal":"2","NoteData":"2015-02-14","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"518","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}