6.8
CVE-2014-2518
- EPSS 0.98%
- Veröffentlicht 20.08.2014 11:17:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Digital Assets Manager Version 6.5
Emc ≫ Digital Assets Manager Version 6.5 Update sp5
Emc ≫ Digital Assets Manager Version 6.5 Update sp6
Emc ≫ Documentum Administrator Version 6.7
Emc ≫ Documentum Administrator Version 6.7 Update sp1
Emc ≫ Documentum Administrator Version 6.7 Update sp2
Emc ≫ Documentum Administrator Version 7.0
Emc ≫ Documentum Administrator Version 7.1
Emc ≫ Documentum Capital Projects Version 1.8
Emc ≫ Documentum Capital Projects Version 1.9
Emc ≫ Documentum Records Manager Version 6.7
Emc ≫ Documentum Records Manager Version 6.7 Update sp1
Emc ≫ Documentum Records Manager Version 6.7 Update sp2
Emc ≫ Documentum Wdk Version 6.7 Update sp1
Emc ≫ Documentum Wdk Version 6.7 Update sp2
Emc ≫ Documentum Webtop Version 6.7
Emc ≫ Documentum Webtop Version 6.7 Update sp1
Emc ≫ Documentum Webtop Version 6.7 Update sp2
Emc ≫ Engineering Plant Facilities Management Solution For Documentum Version 1.7 Update sp1
Emc ≫ Task Space Version 6.7 Update sp1
Emc ≫ Task Space Version 6.7 Update sp2
Emc ≫ Web Publishers Version 6.5 Update sp6
Emc ≫ Web Publishers Version 6.5 Update sp7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.98% | 0.577 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
http://secunia.com/advisories/60563
http://www.securityfocus.com/archive/1/533159/30/0/threaded
http://www.securityfocus.com/bid/69277
http://www.securitytracker.com/id/1030742
https://exchange.xforce.ibmcloud.com/vulnerabilities/95365