CVE-2017-14754: Path Traversal
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cmdatasourcegroupxsd.jsp, parameter: xsddatasourceschemafile filename. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14754?
CVE-2017-14754 is considered a medium severity vulnerability due to its potential for arbitrary file reading.
How do I fix CVE-2017-14754?
To fix CVE-2017-14754, update OpenText Document Sciences xPression to the latest version that addresses this vulnerability.
What causes CVE-2017-14754?
CVE-2017-14754 is caused by improper validation of user-supplied input in the xsd_datasource_schema_file parameter.
What systems are affected by CVE-2017-14754?
CVE-2017-14754 affects OpenText Document Sciences xPression version 4.5SP1 Patch 13 and potentially older versions.
Is CVE-2017-14754 easy to exploit?
Yes, CVE-2017-14754 can be easily exploited by an attacker with knowledge of the system's URL structure.