CVE-2015-0548: Input Validation
The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0548?
CVE-2015-0548 has a medium severity rating as it allows remote authenticated users to perform DQL injection attacks.
How do I fix CVE-2015-0548?
To fix CVE-2015-0548, upgrade to EMC Documentum D2 version 4.2 P16 or 4.5 P03 or later.
What systems are affected by CVE-2015-0548?
CVE-2015-0548 affects EMC Documentum D2 versions 4.1, 4.2, and 4.5 prior to specified patches.
What kind of attack does CVE-2015-0548 enable?
CVE-2015-0548 enables DQL injection attacks which can bypass intended read-access restrictions.
Who is at risk from CVE-2015-0548?
Remote authenticated users of EMC Documentum D2 are at risk from CVE-2015-0548 due to the vulnerability allowing unauthorized data access.