5.8
CVSSv2

CVE-2017-14524

Published: 28/09/2017 Updated: 06/10/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

Vulnerable Product Search on Vulmon Subscribe to Product

opentext documentum webtop 6.8.0160.0073

opentext documentum administrator 7.2.0180.0055

Exploits

OpenText Documentum Administrator version 7201800055 and Documentum Webtop version 6801600073 suffer from an open redirection vulnerability ...