CVE-2014-2511: XSS
Published Aug 20, 2014
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.
Affected Software
24 affected components
EMC Digital Assets Manager=6.5
EMC Digital Assets Manager=6.5-sp5
EMC Digital Assets Manager=6.5-sp6
EMC Documentum Administrator=6.7
EMC Documentum Administrator=6.7-sp1
EMC Documentum Administrator=6.7-sp2
EMC Documentum Administrator=7.0
EMC Documentum Administrator=7.1
EMC Documentum Capital Projects=1.8
EMC Documentum Capital Projects=1.9
EMC Documentum WebTop=6.7
EMC Documentum WebTop=6.7-sp1
EMC Documentum WebTop=6.7-sp2
EMC Engineering Plant Facilities Management Solution For Documentum=1.7
EMC Engineering Plant Facilities Management Solution For Documentum=1.7-sp1
EMC Records Client=6.7
EMC Records Client=6.7-sp1
EMC Records Client=6.7-sp2
EMC Task Space=6.7
EMC Task Space=6.7-sp1
EMC Task Space=6.7-sp2
EMC Web Publishers=6.5
EMC Web Publishers=6.5-sp6
EMC Web Publishers=6.5-sp7
Event History
Aug 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2511?
CVE-2014-2511 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-2511?
To fix CVE-2014-2511, upgrade EMC Documentum WebTop to version 6.7 SP1 P28 or newer.
3
Which versions are affected by CVE-2014-2511?
CVE-2014-2511 affects EMC Documentum WebTop versions prior to 6.7 SP1 P28 and 6.7 SP2 versions before P14.
4
What types of attacks can exploit CVE-2014-2511?
CVE-2014-2511 can be exploited through cross-site scripting attacks, allowing attackers to inject arbitrary scripts.
5
Who is at risk for CVE-2014-2511?
Organizations using the affected versions of EMC Documentum WebTop are at risk of CVE-2014-2511.