CVE-2017-14757
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'jobRunId' SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
OpenText Document Sciences xPression (anteriormente conocido como EMC Document Sciences xPression) v4.5SP1 Patch 13 (otras versiones más antiguas también podrían verse afectadas) es propenso a una inyección SQL: /xDashboard/html/jobhistory/downloadSupportFile.action, parámetro: jobRunId. Para que esta vulnerabilidad sea explotada, un atacante debe autenticarse antes en la aplicación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-27 CVE Reserved
- 2017-10-02 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2017/Oct/8 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42939 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opentext Search vendor "Opentext" | Document Sciences Xpression Search vendor "Opentext" for product "Document Sciences Xpression" | <= 4.5 Search vendor "Opentext" for product "Document Sciences Xpression" and version " <= 4.5" | sp1 |
Affected
|