HIGH
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string
Published Apr 25, 2017
8.8
HIGHCVSS 3.0
EPSS 4.23%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.