CVE-2016-9873

Summary

EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt services by causing execution of arbitrary DQL commands on the application.

Affected Software

VendorProductVersion RangeStatus
n/aEMC Documentum D2 EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6EMC Documentum D2 EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6affected

Weaknesses

  • DQL Injection Vulnerability

ADP Enrichment

CVE Program Container

Additional References

References