CVE-2023-31871: High severity emc documentum content server vulnerability
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dmsecurewriter. The binary has security controls in place preventing creation of a file in a non-owned directory, or as the root user. However, these controls can be carefully bypassed to allow for an arbitrary file write as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31871?
CVE-2023-31871 has been classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2023-31871?
To mitigate CVE-2023-31871, update to OpenText Documentum Content Server version 23.2 or later.
What systems are affected by CVE-2023-31871?
CVE-2023-31871 affects OpenText Documentum Content Server versions before 23.2.
Can CVE-2023-31871 be exploited remotely?
CVE-2023-31871 is primarily an exploitation risk for authenticated users due to privilege escalation capabilities.
What kind of vulnerability is CVE-2023-31871?
CVE-2023-31871 is a local privilege escalation vulnerability affecting Documentum users.