CVE-2014-0622: Critical severity EMC Documentum Foundation Services vulnerability
The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 before P12, and 7.1 before P01 does not properly implement content uploading, which allows remote authenticated users to bypass intended content access restrictions via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EMC Documentum Foundation Services (DFS)to a version that resolves this vulnerability.Fixed in 6.7 SP1 P22
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0622?
CVE-2014-0622 is rated as a medium severity vulnerability.
How do I fix CVE-2014-0622?
To remediate CVE-2014-0622, upgrade EMC Documentum Foundation Services to version 6.7 SP1 P22, 6.7 SP2 P08, 7.0 P12, or 7.1 P01 or later.
What types of systems are affected by CVE-2014-0622?
CVE-2014-0622 affects EMC Documentum Foundation Services versions 6.5 through 7.1.
What is the nature of the vulnerability in CVE-2014-0622?
CVE-2014-0622 allows remote authenticated users to bypass intended content access restrictions during content uploading.
Who can exploit CVE-2014-0622?
CVE-2014-0622 can be exploited by remote authenticated users of the EMC Documentum Foundation Services.