CVE-2015-0547: Input Validation
The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0547?
CVE-2015-0547 is considered a high severity vulnerability due to its potential for DQL injection attacks that can compromise access controls.
How do I fix CVE-2015-0547?
To fix CVE-2015-0547, upgrade to EMC Documentum D2 version 4.2 P16 or higher, or version 4.5 P03 or higher.
Who is affected by CVE-2015-0547?
CVE-2015-0547 affects EMC Documentum D2 versions 4.1, 4.2 prior to P16, and 4.5 prior to P03.
What type of injection vulnerability is CVE-2015-0547?
CVE-2015-0547 is a DQL injection vulnerability that allows attackers to bypass read-access restrictions.
Can CVE-2015-0547 be exploited by unauthenticated users?
No, CVE-2015-0547 requires remote authenticated users to exploit the vulnerability.