NVD

Id
30938  
Name
CVE-2014-2520  
Description
EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request.  
Reject
 
CVSS Version
2  
CVSS Score
6.3  
Severity
Medium  
CVSS Base Score
6.3  
CVSS Impact Subscore
6.9  
CVSS Exploit Subscore
6.8  
CVSS Vector
(AV:N/AC:M/Au:S/C:C/I:N/A:N)  
Pub Date
2017-01-19  
Published
2014-08-20  
Modified Date
2017-01-06  
Seq
2014-2520  

Actions