CVE-2014-2520 - CERT CVE
ID CVE-2014-2520
Sažetak EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request.
Reference
CVSS
Base: 6.3
Impact: 6.9
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:N/AC:M/Au:S/C:C/I:N/A:N
Zadnje važnije ažuriranje 29-08-2017 - 01:34
Objavljeno 20-08-2014 - 11:17