CVE-2016-9873
EMC Documentum D2 4.5 / 4.6 DQL Injection / Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt services by causing execution of arbitrary DQL commands on the application.
EMC Documentum D2 versión 4.5 y EMC Documentum D2 versión 4.6 tiene una Vulnerabilidad de Inyección DQL que potencialmente podría ser explotada por usuarios malintencionados para comprometer el sistema afectado. Un atacante autenticado con pocos privilegios podría explotar potencialmente esta vulnerabilidad para acceder a información, modificar datos o interrumpir los servicios provocando la ejecución de comandos DQL arbitrarios en la aplicación.
EMC Documentum versions 4.5 and 4.6 suffer from DQL injection and cross site scripting vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-06 CVE Reserved
- 2017-01-28 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/540060/30/0/threaded | Third Party Advisory | |
http://www.securityfocus.com/bid/95828 | Third Party Advisory | |
http://www.securitytracker.com/id/1037733 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Documentum D2 Search vendor "Emc" for product "Documentum D2" | 4.5 Search vendor "Emc" for product "Documentum D2" and version "4.5" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Documentum D2 Search vendor "Emc" for product "Documentum D2" | 4.6 Search vendor "Emc" for product "Documentum D2" and version "4.6" | - |
Affected
|