René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

108 lines
3.6 KiB
JSON

{
"id": "CVE-2014-2513",
"sourceIdentifier": "security_alert@emc.com",
"published": "2014-07-08T11:06:01.407",
"lastModified": "2017-01-07T02:59:48.003",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script."
},
{
"lang": "es",
"value": "EMC Documentum Content Server anterior a 6.7 SP1 P28, 6.7 SP2 anterior a P15, 7.0 anterior a P15 y 7.1 anterior a P06 no comprueba debidamente la autorizaci\u00f3n despu\u00e9s de la creaci\u00f3n de un objeto, lo que permite a usuarios remotos autenticados ejecutar c\u00f3digo arbitrario con privilegios de superusuario a trav\u00e9s de una secuencia de comandos personalizada."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "PARTIAL",
"baseScore": 8.2
},
"baseSeverity": "HIGH",
"exploitabilityScore": 6.8,
"impactScore": 9.5,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_content_server:*:sp1:*:*:*:*:*:*",
"versionEndIncluding": "6.7",
"matchCriteriaId": "7B188672-1EC2-4338-A868-BD562962D356"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*",
"matchCriteriaId": "49659818-958F-4B5E-8DA4-B592C67DD13F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:*",
"matchCriteriaId": "B4E00544-98F6-439C-8F4D-822FCAE775CA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8335062A-5A8E-4076-B351-7DFA19CEC818"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "B283F797-6DAA-40E1-9FAB-16FCAA5241B4"
}
]
}
]
}
],
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2014-07/0024.html",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securityfocus.com/bid/68435",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securitytracker.com/id/1030529",
"source": "security_alert@emc.com"
}
]
}