CVE-2017-14527

HIGH

OpenText Documentum Webtop 6.8.0160.0073 - RCE

Title source: llm
STIX 2.1

Description

Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.

References (2)

Core 2
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Sep/58

Scores

CVSS v3 8.8
EPSS 0.0138
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
opentext/documentum_administrator 7.2.0180.0055
opentext/documentum_webtop 6.8.0160.0073
Published Sep 28, 2017
Tracked Since Feb 18, 2026