SQL Injection Vulnerability in OpenText Documentum Content Server
CVE-2017-7221
8.8HIGH
What is CVE-2017-7221?
OpenText Documentum Content Server contains a security flaw due to an inadequate protection mechanism that exposes the system to SQL injection attacks. This vulnerability allows remote authenticated users to execute arbitrary code with super-user privileges by exploiting the dm_bp_transition docbase method and user-created dm_procedure objects. It can be demonstrated by injecting backspace characters into strings. This issue highlights the necessity for robust input validation and database query handling to protect against such exploitations.