6.3

CVE-2014-2521

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensitive object metadata via an RPC command.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EmcDocumentum Content Server Updatesp2 Version <= 6.7
EmcDocumentum Content Server Version6.5 Updatesp1
EmcDocumentum Content Server Version6.5 Updatesp2
EmcDocumentum Content Server Version6.5 Updatesp3
EmcDocumentum Content Server Version6.7 Update-
EmcDocumentum Content Server Version6.7 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.591
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.3 6.8 6.9
AV:N/AC:M/Au:S/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.