CVE-2016-0914
CVE-2016-0914 is a medium-severity vulnerability in Emc Documentum Administrator with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Medium (CVSS 3.x base score 6.3)
- CVSS v2: 6.5
- EPSS exploit prediction: 1% (68th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Emc Documentum Administrator
- Published:
- Last modified:
Description
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.
Frequently asked questions
- What is CVE-2016-0914?
- EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.
- How severe is CVE-2016-0914?
- CVE-2016-0914 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2016-0914 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (68th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2016-0914?
- CVE-2016-0914 primarily affects Emc Documentum Administrator. In total, 8 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2016-0914?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2016-0914 published?
- CVE-2016-0914 was published on 2016-06-23 and last updated on 2026-06-17.
References
Affected products (8)
- cpe:2.3:a:emc:documentum_administrator:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_administrator:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_administrator:7.2:*:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_capital_projects:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_capital_projects:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_taskspace:6.7:sp3:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_webtop:6.8:*:*:*:*:*:*:*
- cpe:2.3:a:emc:documentum_webtop:6.8.1:*:*:*:*:*:*:*
More vulnerabilities in Emc Documentum Administrator
- CVE-2008-0656 — Critical (CVSS 10.0): Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317…
- CVE-2015-4530 — Medium (CVSS 6.8): Cross-site request forgery (CSRF) vulnerability in EMC Documentum WebTop before 6.8P01, Documentum Administrator…
- CVE-2014-2518 — Medium (CVSS 6.8): Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before…
- CVE-2015-4524 — Medium (CVSS 6.5): Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before…
- CVE-2016-8213 — Medium (CVSS 6.1): EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version…
- CVE-2015-4529 — Medium (CVSS 5.8): Open redirect vulnerability in EMC Documentum WebTop before 6.8P02, Documentum Administrator before 7.2P01, Documentum…
All CVEs affecting Emc Documentum Administrator →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →