
CVE-2015-4544 – EMC Documentum Content Server Privilege Escalation
https://notcve.org/view.php?id=CVE-2015-4544
04 Sep 2015 — EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows remote authenticated users to obtain superuser privileges via crafted object operations. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4626. Vulnerabilidad en EMC Documentum Content Server en versiones anteriores a 7.1P20 y 7.2.x en versiones anteriores a 7.2P04, no verifica correctamente la autorización para el acceso de objeto dm_job,... • http://packetstormsecurity.com/files/133441/EMC-Documentum-Content-Server-Privilege-Escalation.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-4531 – EMC Documentum Content Server Privilege Escalation / Code Execution
https://notcve.org/view.php?id=CVE-2015-4531
17 Aug 2015 — EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended restrictions on data access and server actions, via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4622. Vulnerabilidad en EMC Documentum Content Server en versiones anteriores... • https://packetstorm.news/files/id/133143 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-4532 – EMC Documentum Content Server Privilege Escalation
https://notcve.org/view.php?id=CVE-2015-4532
17 Aug 2015 — EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization and does not properly restrict object types, which allows remote authenticated users to run save RPC commands with super-user privileges, and consequently execute arbitrary code, via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2514. Vulnerabilidad en EMC Documentum Content Server en versiones anteriores... • https://packetstorm.news/files/id/133249 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-4533 – OpenText Documentum Content Server SQL Injection
https://notcve.org/view.php?id=CVE-2015-4533
17 Aug 2015 — EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513. Vulnerabilidad en EMC Documentum Content Server en versiones anteriores a 6.7SP1 P32, 6.7SP2 en versiones anteriores a P25, 7.0 en v... • https://packetstorm.news/files/id/142301 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-4534 – EMC Documentum Content Server Privilege Escalation / Code Execution
https://notcve.org/view.php?id=CVE-2015-4534
17 Aug 2015 — Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 allows remote authenticated users to execute arbitrary code by forging a signature for a query string that lacks the method_verb parameter. Vulnerabilidad en Java Method Server (JMS) en EMC Documentum Content Server en versiones anteriores a 6.7SP1 P32, 6.7SP2 en versiones anteriores a P25, 7.0 en versiones anteriores a P19, 7.1 en versiones anteriores a P16 y 7.... • http://seclists.org/bugtraq/2015/Aug/86 • CWE-20: Improper Input Validation •

CVE-2015-4535 – EMC Documentum Content Server Privilege Escalation / Code Execution
https://notcve.org/view.php?id=CVE-2015-4535
17 Aug 2015 — Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02, when __debug_trace__ is configured, allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket. Vulnerabilidad en Java Method Server (JMS) en EMC Documentum Content Server en versiones anteriores a 6.7SP1 P32, 6.7SP2 en versiones anteriores a P25, 7.0 en versiones anteriores a P19, 7.1 e... • http://seclists.org/bugtraq/2015/Aug/86 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-4536 – EMC Documentum Content Server Privilege Escalation / Code Execution
https://notcve.org/view.php?id=CVE-2015-4536
17 Aug 2015 — EMC Documentum Content Server before 7.0 P20, 7.1 before P18, and 7.2 before P02, when RPC tracing is configured, stores certain obfuscated password data in a log file, which allows remote authenticated users to obtain sensitive information by reading this file. Vulnerabilidad en EMC Documentum Content Server en versiones anteriores a 7.0 P20, 7.1 en versiones anteriores a P18 y 7.2 en versiones anteriores a P02, cuando está configurado el rastreo RPC, almacena ciertos datos de contraseñas ofuscadas en un a... • http://seclists.org/bugtraq/2015/Aug/86 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-4626 – EMC Documentum Content Server ESA-2014-105 Fail
https://notcve.org/view.php?id=CVE-2014-4626
17 Dec 2014 — EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515. EMC Documentum Content Server ant... • https://packetstorm.news/files/id/132536 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-4629 – EMC Documentum Content Server Insecure Direct Object Reference
https://notcve.org/view.php?id=CVE-2014-4629
03 Dec 2014 — EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via unspecified vectors related to an insecure direct object reference. EMC Documentum Content Server 7.0, 7.1 anterior a 7.1 P10, y 6.7 anterior a SP2 P19 permite a usuarios remotos autenticados leer o eliminar ficheros arbitrarios a través de vectores no especificados relacionados con una referencia insegura a un objeto directo. EMC Documentum Content Server may... • http://packetstormsecurity.com/files/129376/EMC-Documentum-Content-Server-Insecure-Direct-Object-Reference.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-4621 – EMC Documentum Content Server 7.x / 6.x Privilege Escalation
https://notcve.org/view.php?id=CVE-2014-4621
16 Sep 2014 — EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors. EMC Documentum Content Server anterior a 6.7 SP2 P17, 7.0 hasta P15 y 7.1 anterior a P08 no comprueba debidamente la autorización para subtipos de los tipo... • http://archives.neohapsis.com/archives/bugtraq/2014-09/0093.html • CWE-264: Permissions, Privileges, and Access Controls •