- EPSS 0.22%
- Published 14.02.2015 15:59:00
- Last modified 12.04.2025 10:46:40
The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading...
CVE-2014-2515
- EPSS 1.02%
- Published 20.08.2014 11:17:13
- Last modified 12.04.2025 10:46:40
EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain pr...
- EPSS 0.33%
- Published 26.05.2014 00:25:31
- Last modified 12.04.2025 10:46:40
EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass intended access restrictions and execute arbitrary Documentum Query Language (DQL) queries by calling...