EMC / Documentum D2
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-32264 | CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the… | MEDIUM | 5.8 | Mar 8, 2024 |
| CVE-2016-9873 | EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to com… | MEDIUM | 6.3 | Feb 3, 2017 |
| CVE-2016-9872 | EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has Reflected Cross-Site Scripting Vulnerabilities that could potentially be exploited by malic… | MEDIUM | 6.1 | Feb 3, 2017 |
| CVE-2016-6644 | EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_objec… | MEDIUM | 5.3 | Sep 17, 2016 |
| CVE-2016-0888 | EMC Documentum D2 before 4.6 lacks intended ACLs for configuration objects, which allows remote authenticated users to modify objects via unspecified vectors. | HIGH | 8.8 | Apr 7, 2016 |
| CVE-2015-4537 | Lockbox in EMC Documentum D2 before 4.5 uses a hardcoded passphrase when a server lacks a D2.Lockbox file, which makes it easier for remote authenticated users… | LOW | 3.5 | Aug 22, 2015 |
| CVE-2015-0548 | The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to co… | MEDIUM | 4.0 | Jul 4, 2015 |
| CVE-2015-0547 | The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to con… | MEDIUM | 4.0 | Jul 4, 2015 |
| CVE-2015-0549 | Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before 4.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecifi… | LOW | 3.5 | Jun 28, 2015 |
| CVE-2015-0518 | The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote aut… | HIGH | 9.0 | Feb 14, 2015 |
| CVE-2015-0517 | The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in lo… | MEDIUM | 4.0 | Feb 14, 2015 |
| CVE-2014-2515 | EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdm… | HIGH | 8.5 | Aug 20, 2014 |
| CVE-2014-2504 | EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass intended a… | HIGH | 9.0 | May 23, 2014 |
Showing 1 to 13 of 13 CVEs