PT-2014-4741 · Emc · Emc Documentum Digital Assets Manager
Published
2014-06-06
·
Updated
2014-06-18
·
CVE-2014-2503
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMC Documentum Digital Asset Manager (DAM) versions 6.5 SP3 through 6.5 SP6 before P13
Description
The issue allows remote attackers to conduct Documentum Query Language (DQL) injection attacks, bypassing intended restrictions on querying objects. This is achieved via a crafted parameter in a query string.
Recommendations
For versions 6.5 SP3 through 6.5 SP6 before P13, apply the patch P13 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Documentum Digital Assets Manager