Opentext

Documentum Content Server

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 30.07.2024 15:15:13
  • Zuletzt bearbeitet 21.11.2024 09:42:21

Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.05.2023 17:15:08
  • Zuletzt bearbeitet 22.01.2025 15:15:09

OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security contr...

  • EPSS 2.29%
  • Veröffentlicht 13.10.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authenticated user to hijack an arbitrary file from the Content Server filesyst...

  • EPSS 1.89%
  • Veröffentlicht 13.10.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server stores information about uploaded files in dmr_...

  • EPSS 3.97%
  • Veröffentlicht 13.10.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When ...

  • EPSS 2.61%
  • Veröffentlicht 13.10.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR arc...

Exploit
  • EPSS 1.72%
  • Veröffentlicht 25.04.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docba...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 21.04.2017 02:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 22.02.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users t...