EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability
BID:67868
Info
EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability
| Bugtraq ID: | 67868 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2503 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2014 12:00AM |
| Updated: | Jun 05 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability
EMC Documentum Digital Asset Manager is prone to a DQL-injection vulnerability because the application fails to properly sanitize user-supplied input.
A successful exploit will allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
EMC Documentum Digital Asset Manager 6.5 SP3 through 6.5 SP6 are vulnerable; other versions may also be affected.
EMC Documentum Digital Asset Manager is prone to a DQL-injection vulnerability because the application fails to properly sanitize user-supplied input.
A successful exploit will allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
EMC Documentum Digital Asset Manager 6.5 SP3 through 6.5 SP6 are vulnerable; other versions may also be affected.
Exploit / POC
EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EMC Documentum Digital Asset Manager CVE-2014-2503 Documentum Query Language Injection Vulnerability
References:
References:
- EMC Homepage (EMC)