Multiple vulnerabilities in OpenText Documentum Content Server

2017-10-13 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-15012 Vendor: OpenText Affected products: OpenText Documentum Content Server (all versions) Researcher: Andrey B. Panfilov CVSS v3 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Fix: not available Description: Opentext Documentum Content Server (formerly known

CVE-2017-7221. OpenText Documentum Content Server: arbitrary code execution in dm_bp_transition.ebs docbase method

2017-04-25 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-7221 Vendor: OpenText Affected products: OpenText Documentum Content Server (all versions) Researcher: Andrey B. Panfilov Severity Rating: CVSS v3 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Fix: not available PoC: https://gist.github.com/andreybpanfilov

CVE-2017-7220. OpenText Documentum Content Server: privilege evaluation using crafted RPC save-commands.

2017-04-19 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-7220 Vendor: OpenText Affected products: OpenText Documentum Content Server (all versions) Researcher: Andrey B. Panfilov Severity Rating: CVSS v3 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Fix: not available PoC: https://gist.github.com/andreybpanfilov

CVE-2017-5585: SQL injection in OpenText Documentum Content Server 7.3 (PostgreSQL builds only)

2017-02-15 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-5585 Vendor: OpenText Affected products: OpenText Documentum Content Server 7.3 (PostgreSQL builds only) Researcher: Andrey B. Panfilov Severity Rating: CVSS v3 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Fix: not available Description: Previously announced

CVE-2017-5586: Remote code execution in OpenText Documentum D2

2017-02-15 Thread Andrey B. Panfilov
CVE Identifier: CVE-2017-5586 Vendor: OpenText Affected products: Documentum D2 version 4.x Researcher: Andrey B. Panfilov Severity Rating: CVSS v3 Base Score: 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) Description: Document D2 contains vulnerable BeanShell (bsh) and Apache Commons libraries

HTTP session poisoning in EMC Documentum WDK-based applications causes arbitrary code execution and privilege elevation

2016-07-04 Thread Andrey B. Panfilov
announced the remediation for it - https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0914 (Un)fortunately the fix announced by vendor in CVE-2016-0914 does remediate nothing. Demonstration: https://youtu.be/OarCJ4vB36s __ Regards, Andrey B. Panfilov