578
VMScore

CVE-2017-14526

Published: 28/09/2017 Updated: 06/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.

Vulnerable Product Search on Vulmon Subscribe to Product

opentext documentum administrator 7.2.0180.0055

opentext documentum webtop 6.8.0160.0073

Exploits

OpenText Documentum Administrator version 7201800055 and Documentum Webtop version 6801600073 suffer from XML external entity injection vulnerabilities ...