CVE-2014-4621 is a critical authorization bypass vulnerability affecting EMC Documentum Content Server versions prior to 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08. This flaw allows authenticated remote attackers to gain super-user privileges, enabling them to create system objects, bypass data access restrictions, and execute unauthorized server actions. With a CVSS score of 8.5 (High), exploitation requires medium attack complexity but grants complete confidentiality, integrity, and availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.7CPE matchmatch criteria | cpe:2.3:a:emc:documentum_content_server:*:sp2:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:emc:documentum_content_server:6.0:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:emc:documentum_content_server:6.5:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:emc:documentum_content_server:6.5:sp1:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:emc:documentum_content_server:6.5:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.