CVE-2014-4622
EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended restrictions on data access and server actions, via unspecified vectors.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
- EPSS
- 2.56% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- emc/documentum content server
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html
- http://secunia.com/advisories/61251
- http://www.securityfocus.com/bid/69819
- http://www.securitytracker.com/id/1030855
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95990
- http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html
- http://secunia.com/advisories/61251
- http://www.securityfocus.com/bid/69819
- http://www.securitytracker.com/id/1030855
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95990
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.