CVE-2014-4626
Estado: ModificadaAlta (9)—
EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
- Puntuación base: 9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.99%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://www.kb.cert.org/vuls/id/315340
- http://www.kb.cert.org/vuls/id/386056
- http://www.kb.cert.org/vuls/id/874632
- https://docs.google.com/spreadsheets/d/1DiiUPCPvmaliWcfwPSc36y2mDvuidkDKQBWqaIuJi0A/edit?usp=sharing
- http://www.kb.cert.org/vuls/id/315340
- http://www.kb.cert.org/vuls/id/386056
- http://www.kb.cert.org/vuls/id/874632
- https://docs.google.com/spreadsheets/d/1DiiUPCPvmaliWcfwPSc36y2mDvuidkDKQBWqaIuJi0A/edit?usp=sharing
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-4626",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-12-17T01:59:00.067",
"references": [
{
"url": "http://www.kb.cert.org/vuls/id/315340",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "security_alert@emc.com"
},
{
"url": "http://www.kb.cert.org/vuls/id/386056",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "security_alert@emc.com"
},
{
"url": "http://www.kb.cert.org/vuls/id/874632",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "security_alert@emc.com"
},
{
"url": "https://docs.google.com/spreadsheets/d/1DiiUPCPvmaliWcfwPSc36y2mDvuidkDKQBWqaIuJi0A/edit?usp=sharing",
"source": "security_alert@emc.com"
},
{
"url": "http://www.kb.cert.org/vuls/id/315340",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/386056",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/874632",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.google.com/spreadsheets/d/1DiiUPCPvmaliWcfwPSc36y2mDvuidkDKQBWqaIuJi0A/edit?usp=sharing",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain privileges by (1) placing a command in a dm_job object and setting this object's owner to a privileged user or placing a rename action in a dm_job_request object and waiting for a (2) dm_UserRename or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2515."
},
{
"lang": "es",
"value": "EMC Documentum Content Server anterior a 6.7 SP1 P29, 6.7 SP2 anterior a P18, 7.0 anterior a P16, y 7.1 anterior a P09 permite a usuarios remotos autenticados ganar privilegios mediante (1) lla colocación de un comando en un objeto dm_job y la configutación del dueño de este objeto a un usuario privilegiado o la colocación de una acción de renombrar en un objeto dm_job_request y la espera a una tarea de servicio (2) dm_UserRename o (3) dm_GroupRename, también conocido como ESA-2014-105. NOTA: esta vulnerabilidad existe debido a una solución incompleta para CVE-2014-2515."
}
],
"lastModified": "2026-06-17T00:10:21.870",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:emc:documentum_content_server:*:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B188672-1EC2-4338-A868-BD562962D356",
"versionEndIncluding": "6.7"
},
{
"criteria": "cpe:2.3:a:emc:documentum_content_server:6.7:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49659818-958F-4B5E-8DA4-B592C67DD13F"
},
{
"criteria": "cpe:2.3:a:emc:documentum_content_server:6.7:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4E00544-98F6-439C-8F4D-822FCAE775CA"
},
{
"criteria": "cpe:2.3:a:emc:documentum_content_server:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8335062A-5A8E-4076-B351-7DFA19CEC818"
},
{
"criteria": "cpe:2.3:a:emc:documentum_content_server:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B283F797-6DAA-40E1-9FAB-16FCAA5241B4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}