Show filters
144 Total Results
Displaying 131-140 of 144
Sort by:
Attacker Value
Unknown
CVE-2017-7221
Disclosure Date: April 25, 2017 (last updated November 26, 2024)
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.
0
Attacker Value
Unknown
CVE-2017-7220
Disclosure Date: April 21, 2017 (last updated November 26, 2024)
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532.
0
Attacker Value
Unknown
CVE-2017-5585
Disclosure Date: February 22, 2017 (last updated November 26, 2024)
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL commands via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2520.
0
Attacker Value
Unknown
CVE-2017-5586
Disclosure Date: February 22, 2017 (last updated November 26, 2024)
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
0
Attacker Value
Unknown
CVE-2015-6530
Disclosure Date: August 20, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboard.jsp.
0
Attacker Value
Unknown
CVE-2013-6806
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.
0
Attacker Value
Unknown
CVE-2013-6805
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.
0
Attacker Value
Unknown
CVE-2013-6994
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
0
Attacker Value
Unknown
CVE-2013-6807
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
0
Attacker Value
Unknown
CVE-2013-3243
Disclosure Date: October 28, 2013 (last updated October 05, 2023)
Unspecified vulnerability in OpenText/IXOS ECM for SAP NetWeaver allows remote attackers to execute arbitrary ABAP code via unknown vectors.
0