PT-2017-16592 · Opentext+1 · Opentext Documentum Content Server+1

Publicado

2017-02-22

·

Atualizado

2017-03-02

·

CVE-2017-5585

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText Documentum Content Server versions 7.3
Description The issue allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL commands via a crafted request, due to the improper restriction of DQL hints when the PostgreSQL Database is used and the return top results row based config option is false.
Recommendations For OpenText Documentum Content Server version 7.3, set the return top results row based config option to true to mitigate the risk of DQL injection attacks. Additionally, consider restricting access to the DQL functionality until a more comprehensive fix is available.

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5585

Produtos afetados

Opentext Documentum Content Server
Postgresql Database