6.5
CVSSv3

CVE-2017-14754

Published: 03/10/2017 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N

Vulnerability Summary

OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource_group_xsd.jsp, parameter: xsd_datasource_schema_file filename. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

Vulnerable Product Search on Vulmon Subscribe to Product

opentext document sciences xpression

Exploits

OpenText Document Sciences xPression version 45SP1 Patch 13 suffers from an arbitrary file read vulnerability ...