Security Advisory

CVE-2017-14758

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-02 17:00:00
Last updated 2024-08-05 19:34:39
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.