SQL Injection Vulnerability in OpenText Documentum Content Server
CVE-2017-7221

8.8HIGH

Key Information:

Vendor
Opentext
Vendor
CVE Published:
25 April 2017

Summary

OpenText Documentum Content Server contains a security flaw due to an inadequate protection mechanism that exposes the system to SQL injection attacks. This vulnerability allows remote authenticated users to execute arbitrary code with super-user privileges by exploiting the dm_bp_transition docbase method and user-created dm_procedure objects. It can be demonstrated by injecting backspace characters into strings. This issue highlights the necessity for robust input validation and database query handling to protect against such exploitations.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.