Vulnerabilities (CVE)

Filtered by vendor Emc Subscribe
Filtered by product Documentum D2
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-6644 1 Emc 1 Documentum D2 2017-08-13 5.0 MEDIUM 5.3 MEDIUM
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
CVE-2016-9872 1 Emc 1 Documentum D2 2017-07-25 4.3 MEDIUM 6.1 MEDIUM
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has Reflected Cross-Site Scripting Vulnerabilities that could potentially be exploited by malicious users to compromise the affected system.
CVE-2016-9873 1 Emc 1 Documentum D2 2017-07-25 6.5 MEDIUM 6.3 MEDIUM
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt services by causing execution of arbitrary DQL commands on the application.