CVE-2017-14960: SQL Injection
Published Jan 4, 2018
·Updated
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.
Affected Software
1 affected component
OpenText Document Sciences xPression<=4.5
Event History
Jan 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14960?
CVE-2017-14960 is classified as a high-severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2017-14960?
To fix CVE-2017-14960, update OpenText Document Sciences xPression to a version that includes the necessary security patches.
3
What are the risks associated with CVE-2017-14960?
The risks of CVE-2017-14960 include unauthorized access to sensitive data and potential data manipulation or loss.
4
Who is affected by CVE-2017-14960?
Users of OpenText Document Sciences xPression v4.5SP1 Patch 13 are affected by CVE-2017-14960.
5
What type of vulnerability is CVE-2017-14960?
CVE-2017-14960 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL code on the database.