CVE-2014-2518: Emc Digital Assets Manager

Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.

Affected products

  • Emc Digital Assets Manager: version 6.5 only
  • Emc Documentum Administrator: version 6.7 only; version 7.0 only; version 7.1 only
  • Emc Documentum Capital Projects: version 1.8 only; version 1.9 only
  • Emc Documentum Records Manager: version 6.7 only
  • Emc Documentum Wdk: version 6.7 only
  • Emc Documentum Webtop: version 6.7 only
  • Emc Engineering Plant Facilities Management Solution For Documentum: version 1.7 only
  • Emc Task Space: version 6.7 only
  • Emc Web Publishers: version 6.5 only

Published 2014-08-20. Last modified 2026-06-17.