CVE-2017-15012
HIGHOpenText Documentum Content Server < 7.3 - Authenticated Arbitrary File Read via PUT_FILE RPC Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15012. PoCs published by Andrey B. Panfilov.
AI-analyzed exploit summary This exploit leverages an input validation flaw in the PUT_FILE RPC command of OpenText Documentum Content Server to hijack arbitrary files, leading to privilege escalation by stealing the dfc.keystore and impersonating a superuser.
Description
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authenticated user to hijack an arbitrary file from the Content Server filesystem; because some files on the Content Server filesystem are security-sensitive, this leads to privilege escalation.
Exploits (1)
This exploit leverages an input validation flaw in the PUT_FILE RPC command of OpenText Documentum Content Server to hijack arbitrary files, leading to privilege escalation by stealing the dfc.keystore and impersonating a superuser.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H