File Hijacking Vulnerability in OpenText Documentum Content Server
CVE-2017-15012
8.8HIGH
What is CVE-2017-15012?
The OpenText Documentum Content Server, up to version 7.3, does not adequately validate input for the PUT_FILE RPC-command. This lack of validation enables authenticated users to manipulate the system, thereby hijacking arbitrary files from the server's filesystem. Since some of these files contain sensitive security information, this flaw poses a significant risk of privilege escalation, allowing users to gain unauthorized access to critical data.