CVE-2014-2504: Critical severity EMC Documentum D2 vulnerability
EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass intended access restrictions and execute arbitrary Documentum Query Language (DQL) queries by calling (1) a core method or (2) a D2FS web-service method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2504?
CVE-2014-2504 is classified as a medium severity vulnerability due to its potential impact on data confidentiality.
How do I fix CVE-2014-2504?
Fixing CVE-2014-2504 involves upgrading to the latest patched version of EMC Documentum D2 as specified in the vendor's advisories.
Who is affected by CVE-2014-2504?
Users of EMC Documentum D2 versions 3.1, 3.1 SP1, 4.0, 4.1, and 4.2 are affected by CVE-2014-2504.
What type of attack is possible with CVE-2014-2504?
CVE-2014-2504 allows remote authenticated users to execute arbitrary Documentum Query Language (DQL) queries, leading to unauthorized access.
Is there a workaround for CVE-2014-2504?
While upgrading is the recommended solution for CVE-2014-2504, limiting user roles and permissions can serve as an interim workaround.