EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability
BID:67916
Info
EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability
| Bugtraq ID: | 67916 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2507 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2014 12:00AM |
| Updated: | Dec 16 2014 06:57AM |
| Credit: | EMC |
| Vulnerable: |
EMC Documentum Content Server 6.7 EMC Documentum Content Server 6.6 P02 EMC Documentum Content Server 6.6 EMC Documentum Content Server 6.5 SP3 P02 EMC Documentum Content Server 6.5 SP2 P02 EMC Documentum Content Server 6.5 EMC Documentum Content Server 6.0 EMC Documentum Content Server 5 |
| Not Vulnerable: | |
Discussion
EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability
EMC Documentum Content Server is prone to a remote shell command-injection vulnerability.
A remote attacker can leverage this issue to to execute code and perform unauthorized actions within the context of the application.
The following products are vulnerable:
EMC Documentum Content Server versions of 7.1
EMC Documentum Content Server versions of 7.0
EMC Documentum Content Server versions of 6.7 SP2
EMC Documentum Content Server versions of 6.7 SP1
EMC Documentum Content Server versions prior to 6.7 SP1
EMC Documentum Content Server is prone to a remote shell command-injection vulnerability.
A remote attacker can leverage this issue to to execute code and perform unauthorized actions within the context of the application.
The following products are vulnerable:
EMC Documentum Content Server versions of 7.1
EMC Documentum Content Server versions of 7.0
EMC Documentum Content Server versions of 6.7 SP2
EMC Documentum Content Server versions of 6.7 SP1
EMC Documentum Content Server versions prior to 6.7 SP1
Exploit / POC
EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EMC Documentum Content Server CVE-2014-2507 Shell Command Injection Vulnerability
References:
References:
- EMC Homepage (EMC)