CVE-2017-14757: SQL Injection
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14757?
CVE-2017-14757 is classified as a high severity vulnerability due to the potential for SQL Injection exploitation.
How do I fix CVE-2017-14757?
To fix CVE-2017-14757, apply the necessary security patches from OpenText for Document Sciences xPression v4.5SP1 Patch 13 or later.
What systems are affected by CVE-2017-14757?
CVE-2017-14757 affects OpenText Document Sciences xPression versions up to and including 4.5SP1.
What kind of attack can exploit CVE-2017-14757?
CVE-2017-14757 can be exploited through SQL Injection attacks targeting the jobRunId parameter.
Is there a workaround for CVE-2017-14757?
Currently, no official workaround is provided for CVE-2017-14757 other than applying the available patches.