Multiple EMC Documentum Products CVE-2014-4638 Unspecified Frame Injection Vulnerability

BID:71877

Info

Multiple EMC Documentum Products CVE-2014-4638 Unspecified Frame Injection Vulnerability

Bugtraq ID: 71877
Class: Input Validation Error
CVE: CVE-2014-4638
Remote: Yes
Local: No
Published: Jan 05 2015 12:00AM
Updated: Jan 05 2015 12:00AM
Credit: The vendor reported this issue.
Vulnerable: EMC Records Client 6.7 SP1
EMC Records Client 6.7 SP2
EMC Records Client 6.7
EMC Engineering Plant Facilities Management Solution for Documentum 1.7SP1
EMC Documentum Webtop 6.7 SP2
EMC Documentum Webtop 6.7 SP1
EMC Documentum Webtop 6.7 SP1
EMC Documentum Webtop 6.7
EMC Documentum Web Publisher 6.5SP7
EMC Documentum Web Publisher 6.5 SP5
EMC Documentum Web Publisher 6.5 SP4
EMC Documentum Web Publisher 6.5 Sp3
EMC Documentum Web Publisher 6.5 Sp2
EMC Documentum Web Publisher 6.5 Sp1
EMC Documentum WDK 6.7SP1 P28
EMC Documentum WDK 6.7SP1
EMC Documentum WDK 6.7 SP2
EMC Documentum WDK 6.7 SP1
EMC Documentum WDK 6.7 SP1
EMC Documentum WDK 6.7
EMC Documentum Taskspace 6.7 SP2
EMC Documentum Taskspace 6.7 SP1 P25
EMC Documentum Taskspace 6.7 SP1
EMC Documentum Taskspace 6.7 SP1
EMC Documentum Taskspace 6.7
EMC Documentum Digital Asset Manager 6.5 SP6
EMC Documentum Digital Asset Manager 6.5 SP5
EMC Documentum Digital Asset Manager 6.5 SP4
EMC Documentum Digital Asset Manager 6.5 SP3
EMC Documentum Capital Projects 1.9
EMC Documentum Capital Projects 1.8 P11
EMC Documentum Capital Projects 1.8
EMC Documentum Capital Projects 1.7
EMC Documentum Administrator 7.1
EMC Documentum Administrator 7.0 P15
EMC Documentum Administrator 7.0
EMC Documentum Administrator 6.7SP2 P15
EMC Documentum Administrator 6.7SP2
EMC Documentum Administrator 6.7SP1 P28
EMC Documentum Administrator 6.7 SP1
EMC Documentum Administrator 6.7 SP1
Not Vulnerable: EMC Documentum Webtop 6.8

Discussion

Multiple EMC Documentum Products CVE-2014-4638 Unspecified Frame Injection Vulnerability

Multiple EMC Documentum products are prone to an unspecified frame-injection vulnerability.

An attacker can exploit this issue to conduct phishing attacks. Successful exploits will allow the attacker to gain unauthorized access or obtain sensitive information.

Exploit / POC

Multiple EMC Documentum Products CVE-2014-4638 Unspecified Frame Injection Vulnerability

Attackers can exploit this issue using browser.

References

Multiple EMC Documentum Products CVE-2014-4638 Unspecified Frame Injection Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report