CVE-2014-4622

EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended restrictions on data access and server actions, via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emc:documentum_content_server:*:sp2:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.5:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.5:sp1:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.5:sp2:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.5:sp3:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.6:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:6.7:sp1:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:10

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html - () http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html -
References () http://secunia.com/advisories/61251 - () http://secunia.com/advisories/61251 -
References () http://www.securityfocus.com/bid/69819 - () http://www.securityfocus.com/bid/69819 -
References () http://www.securitytracker.com/id/1030855 - () http://www.securitytracker.com/id/1030855 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/95990 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/95990 -

Information

Published : 2014-09-17 10:55

Updated : 2024-11-21 02:10


NVD link : CVE-2014-4622

Mitre link : CVE-2014-4622

CVE.ORG link : CVE-2014-4622


JSON object : View

Products Affected

emc

  • documentum_content_server
CWE
CWE-264

Permissions, Privileges, and Access Controls