Vulnerability Name: | CVE-2015-0548 (CCN-104310) | ||||||||
Assigned: | 2014-12-17 | ||||||||
Published: | 2015-07-01 | ||||||||
Updated: | 2016-12-28 | ||||||||
Summary: | The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-0548 Source: BUGTRAQ Type: UNKNOWN 20150701 ESA-2015-108: EMC Documentum D2 Multiple DQL Injection Vulnerabilities Source: CCN Type: EMC Security Advisory ESA-2015-108 EMC Documentum D2 Multiple DQL Injection Vulnerabilities Source: SECTRACK Type: UNKNOWN 1032769 Source: XF Type: UNKNOWN documentum-cve20150548-dql-injection(104310) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |