// For flags

CVE-2016-0914

 

Severity Score

6.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.

EMC Documentum WebTop 6.8 en versiones anteriores a Patch 13 y 6.8.1 en versiones anteriores a Patch 02, Documentum Administrator 7.x en versiones anteriores a 7.2 Patch 13, Documentum Capital Projects 1.9 en versiones anteriores a Patch 23 y 1.10 en versiones anteriores a Patch 10 y Documentum TaskSpace 6.7 SP3 permite a usuarios remotos autenticados eludir las restricciones de acceso previstas y ejecutar comandos IAPI/IDQL arbitrarios a través de la interfaz IAPI/IDQL.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-12-17 CVE Reserved
  • 2016-06-22 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Emc
Search vendor "Emc"
Documentum Administrator
Search vendor "Emc" for product "Documentum Administrator"
7.0
Search vendor "Emc" for product "Documentum Administrator" and version "7.0"
-
Affected
Emc
Search vendor "Emc"
Documentum Administrator
Search vendor "Emc" for product "Documentum Administrator"
7.1
Search vendor "Emc" for product "Documentum Administrator" and version "7.1"
-
Affected
Emc
Search vendor "Emc"
Documentum Administrator
Search vendor "Emc" for product "Documentum Administrator"
7.2
Search vendor "Emc" for product "Documentum Administrator" and version "7.2"
-
Affected
Emc
Search vendor "Emc"
Documentum Capital Projects
Search vendor "Emc" for product "Documentum Capital Projects"
1.9
Search vendor "Emc" for product "Documentum Capital Projects" and version "1.9"
-
Affected
Emc
Search vendor "Emc"
Documentum Capital Projects
Search vendor "Emc" for product "Documentum Capital Projects"
1.10
Search vendor "Emc" for product "Documentum Capital Projects" and version "1.10"
-
Affected
Emc
Search vendor "Emc"
Documentum Taskspace
Search vendor "Emc" for product "Documentum Taskspace"
6.7
Search vendor "Emc" for product "Documentum Taskspace" and version "6.7"
sp3
Affected
Emc
Search vendor "Emc"
Documentum Webtop
Search vendor "Emc" for product "Documentum Webtop"
6.8
Search vendor "Emc" for product "Documentum Webtop" and version "6.8"
-
Affected
Emc
Search vendor "Emc"
Documentum Webtop
Search vendor "Emc" for product "Documentum Webtop"
6.8.1
Search vendor "Emc" for product "Documentum Webtop" and version "6.8.1"
-
Affected