CVE-2014-4626: Critical severity opentext documentum content server vulnerability
EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dmjob object and setting this object's owner to a privileged user or placing a rename action in a dmjobrequest object and waiting for a (2) dmUserRename or (3) dmGroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4626?
CVE-2014-4626 is considered a medium severity vulnerability due to its exploitation potential by remote authenticated users.
How do I fix CVE-2014-4626?
To fix CVE-2014-4626, upgrade EMC Documentum Content Server to versions 6.7 SP1 P29 or newer, 6.7 SP2 P18 or newer, 7.0 P16 or newer, or 7.1 P09 or newer.
What types of users are affected by CVE-2014-4626?
CVE-2014-4626 primarily affects remote authenticated users with the ability to create or manipulate certain objects within the EMC Documentum environment.
What are the implications of exploiting CVE-2014-4626?
Exploiting CVE-2014-4626 allows a remote authenticated user to gain elevated privileges, potentially leading to unauthorized actions within the system.
Which versions of EMC Documentum Content Server are vulnerable to CVE-2014-4626?
Versions vulnerable to CVE-2014-4626 include EMC Documentum Content Server prior to 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09.