CVE-2017-5586: Input Validation
Published Feb 22, 2017
·Updated
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
Affected Software
7 affected components
OpenText Documentum D2=4.0
OpenText Documentum D2=4.1
OpenText Documentum D2=4.2
OpenText Documentum D2=4.3
OpenText Documentum D2=4.4
OpenText Documentum D2=4.5
OpenText Documentum D2=4.6
Event History
Feb 22, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5586?
CVE-2017-5586 is rated as critical due to its ability to allow remote attackers to execute arbitrary commands.
2
How do I fix CVE-2017-5586?
To fix CVE-2017-5586, upgrade to the latest version of OpenText Documentum D2 that addresses this vulnerability.
3
What versions of OpenText Documentum D2 are affected by CVE-2017-5586?
CVE-2017-5586 affects OpenText Documentum D2 versions 4.0 through 4.6.
4
What type of attack is enabled by CVE-2017-5586?
CVE-2017-5586 allows remote code execution through a crafted serialized Java object.
5
Is there a patch available for CVE-2017-5586?
Yes, OpenText has released patches for affected versions of OpenText Documentum D2 to mitigate CVE-2017-5586.