CVE-2017-14527
Last modified
CVE-2017-14527 is a vulnerability of currently unknown severity. Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opentext | Documentum Administrator | 7.2.0180.0055 |
| Opentext | Documentum Webtop | 6.8.0160.0073 |
References
- http://seclists.org/fulldisclosure/2017/Sep/58Exploit, Mailing List, Third Party Advisory
- https://knowledge.opentext.com/knowledge/llisapi.dll/Open/68982774Permissions Required
- http://seclists.org/fulldisclosure/2017/Sep/58Exploit, Mailing List, Third Party Advisory
- https://knowledge.opentext.com/knowledge/llisapi.dll/Open/68982774Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14527?
How severe is CVE-2017-14527?
How do I fix CVE-2017-14527?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14521In WonderCMS 2.3.1, the upload functionality accepts random …
- CVE-2017-14522In WonderCMS 2.3.1, the application's input fields accept ar…6.1
- CVE-2017-14523WonderCMS 2.3.1 is vulnerable to an HTTP Host header injecti…
- CVE-2017-14524Multiple open redirect vulnerabilities in OpenText Documentu…
- CVE-2017-14525Multiple open redirect vulnerabilities in OpenText Documentu…
- CVE-2017-14526Multiple XML external entity (XXE) vulnerabilities in the Op…
- CVE-2017-14528The TIFFSetProfiles function in coders/tiff.c in ImageMagick…6.5
- CVE-2017-14529The pe_print_idata function in peXXigen.c in the Binary File…
- CVE-2017-1453IBM Security Access Manager Appliance 9.0.3 could allow a re…
- CVE-2017-14530WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7…8
- CVE-2017-14531ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUN…
- CVE-2017-14532ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIg…
Are you affected by CVE-2017-14527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
