CVE-2014-0630: Medium severity EMC Documentum TaskSpace vulnerability
Published Mar 6, 2014
·Updated
EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 allows remote authenticated users to read arbitrary files via a modified imaging-service URL.
Affected Software
2 affected components
EMC Documentum TaskSpace=6.7-sp1
EMC Documentum TaskSpace=6.7-sp2
Event History
Mar 6, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
via NVD·11:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0630?
CVE-2014-0630 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-0630?
To fix CVE-2014-0630, upgrade EMC Documentum TaskSpace to version 6.7SP1 P25 or 6.7SP2 P11 or later.
3
Who is affected by CVE-2014-0630?
CVE-2014-0630 affects EMC Documentum TaskSpace versions 6.7SP1 before P25 and 6.7SP2 before P11.
4
What can an attacker do with CVE-2014-0630?
An attacker exploiting CVE-2014-0630 can read arbitrary files on the server as a remote authenticated user.
5
Is authentication needed to exploit CVE-2014-0630?
Yes, CVE-2014-0630 requires the attacker to be an authenticated user to exploit the vulnerability.