Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-2511


Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.


Published

2014-08-20T11:17:13.780

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emc digital_assets_manager 6.5 Yes
Application emc digital_assets_manager 6.5 Yes
Application emc digital_assets_manager 6.5 Yes
Application emc documentum_administrator 6.7 Yes
Application emc documentum_administrator 6.7 Yes
Application emc documentum_administrator 6.7 Yes
Application emc documentum_administrator 7.0 Yes
Application emc documentum_administrator 7.1 Yes
Application emc documentum_capital_projects 1.8 Yes
Application emc documentum_capital_projects 1.9 Yes
Application emc documentum_webtop 6.7 Yes
Application emc documentum_webtop 6.7 Yes
Application emc documentum_webtop 6.7 Yes
Application emc engineering_plant_facilities_management_solution_for_documentum 1.7 Yes
Application emc engineering_plant_facilities_management_solution_for_documentum 1.7 Yes
Application emc records_client 6.7 Yes
Application emc records_client 6.7 Yes
Application emc records_client 6.7 Yes
Application emc task_space 6.7 Yes
Application emc task_space 6.7 Yes
Application emc task_space 6.7 Yes
Application emc web_publishers 6.5 Yes
Application emc web_publishers 6.5 Yes
Application emc web_publishers 6.5 Yes

References