CVE-2014-2511: Emc Digital Assets Manager

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.

Affected products

  • Emc Digital Assets Manager: version 6.5 only
  • Emc Documentum Administrator: version 6.7 only; version 7.0 only; version 7.1 only
  • Emc Documentum Capital Projects: version 1.8 only; version 1.9 only
  • Emc Documentum Webtop: version 6.7 only
  • Emc Engineering Plant Facilities Management Solution For Documentum: version 1.7 only
  • Emc Records Client: version 6.7 only
  • Emc Task Space: version 6.7 only
  • Emc Web Publishers: version 6.5 only

Published 2014-08-20. Last modified 2026-06-17.