CVE-2017-7220: Input Validation
OpenText Documentum Content Server allows superuser access via sysobjsave or save of a crafted object, followed by an unauthorized "UPDATE dmdbo.dmusers SET userprivileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7220?
CVE-2017-7220 is classified as a critical vulnerability due to its potential for superuser access escalation.
How do I fix CVE-2017-7220?
To remediate CVE-2017-7220, ensure that your OpenText Documentum Content Server is updated to the latest version that contains the patch for this vulnerability.
What systems are affected by CVE-2017-7220?
CVE-2017-7220 affects all versions of OpenText Documentum Content Server.
What types of attacks can exploit CVE-2017-7220?
CVE-2017-7220 can be exploited through RPC save-commands attacks that enable unauthorized superuser access.
Who is impacted by CVE-2017-7220?
Organizations using vulnerable versions of OpenText Documentum Content Server are impacted, especially those with sensitive or critical data.