VYPR
Unrated severityNVD Advisory· Published Sep 17, 2014· Updated May 6, 2026

CVE-2014-4621

CVE-2014-4621

Description

EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors.

Affected products

11
  • cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.5:sp1:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.5:sp2:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.5:sp3:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:6.7:sp1:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:documentum_content_server:*:sp2:*:*:*:*:*:*range: <=6.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.