Privilege Escalation Vulnerability in OpenText Documentum Content Server
CVE-2023-31871
7.8HIGH
What is CVE-2023-31871?
OpenText Documentum Content Server prior to version 23.2 contains a vulnerability that enables a non-privileged user to escalate their privileges to root. The flaw arises from the presence of a SUID binary, dm_secure_writer, with insufficient security controls. Although the binary restricts file creation in non-owned directories when executed as a non-root user, sophisticated exploitation techniques can bypass these restrictions, facilitating unauthorized root-level file writing. This vulnerability poses significant risks, as it can allow attackers to manipulate system files and gain full control of the affected server.