CVE-2017-14526

HIGH

OpenText Documentum Administrator 7.2.0180.0055 - RCE

Title source: llm
STIX 2.1

Description

Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Sep/58
Permissions Required, Vendor Advisory x_refsource_confirm
https://knowledge.opentext.com/knowledge/llisapi.dll/Open/68982774

Scores

CVSS v3 8.8
EPSS 0.0115
EPSS Percentile 62.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
opentext/documentum_administrator 7.2.0180.0055
opentext/documentum_webtop 6.8.0160.0073
Published Sep 28, 2017
Tracked Since Feb 18, 2026