CVE-2018-7660: XSS
Published Apr 11, 2018
·Updated
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download docbase or username parameter.
Affected Software
1 affected component
OpenText Documentum D2=4.6.0030
Event History
Apr 11, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7660?
CVE-2018-7660 has a medium severity level, indicating a potential risk for exploitation.
2
How do I fix CVE-2018-7660?
To fix CVE-2018-7660, apply the latest security patches provided by OpenText for Documentum D2.
3
What types of attacks can CVE-2018-7660 enable?
CVE-2018-7660 can enable reflected cross-site scripting attacks that may compromise user sessions.
4
Who is affected by CVE-2018-7660?
CVE-2018-7660 affects users of OpenText Documentum D2 version 4.6.0030.
5
What parameters are involved in the CVE-2018-7660 vulnerability?
CVE-2018-7660 involves the servlet parameters _docbase and _username.