CVE-2023-31871
HIGHOpenText Documentum Content Server <23.2 - Privilege Escalation
Title source: llmDescription
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory, or as the root user. However, these controls can be carefully bypassed to allow for an arbitrary file write as root.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://gist.github.com/picar0jsu/a8e623639da34f36202ce5e436668de7
Scores
CVSS v3
7.8
EPSS
0.0001
EPSS Percentile
0.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-732
Status
published
Products (1)
opentext/documentum_content_server
< 23.2
Published
May 18, 2023
Tracked Since
Feb 18, 2026