CVE-2014-4626
Last modified
CVE-2014-4626 is a vulnerability of currently unknown severity. EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515.. EPSS estimates a 3.99% chance of exploitation in the next 30 days.
Description
EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Emc | Documentum Content Server | <= 6.7 | Sp1 |
| Emc | Documentum Content Server | 6.7 | — |
| Emc | Documentum Content Server | 7.0 | — |
| Emc | Documentum Content Server | 7.1 | — |
References
- http://www.kb.cert.org/vuls/id/315340Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/386056Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/874632Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/315340Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/386056Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/874632Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4626?
How severe is CVE-2014-4626?
How do I fix CVE-2014-4626?
Are you affected by CVE-2014-4626?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
