CVE-2014-2515: High severity opentext documentum d2 vulnerability
EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain privileges via a request for a superuser ticket.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2515?
CVE-2014-2515 has a high severity due to its potential for privilege escalation by remote authenticated users.
How do I fix CVE-2014-2515?
To resolve CVE-2014-2515, apply the appropriate patches for EMC Documentum D2 versions 3.1, 4.0, 4.1, and 4.2 as specified by the vendor.
What versions of EMC Documentum D2 are affected by CVE-2014-2515?
CVE-2014-2515 affects EMC Documentum D2 versions 3.1, 3.1SP1, 4.0, 4.1, and 4.2 before specified patches.
What are the implications of CVE-2014-2515?
CVE-2014-2515 allows remote authenticated users to gain superuser privileges, which can lead to unauthorized access and data manipulation.
Is there a workaround for CVE-2014-2515?
There are no officially recommended workarounds for CVE-2014-2515; applying the vendor patches is strongly advised.