CVE-2017-15014 describes a design flaw in OpenText Documentum Content Server versions through 7.3, allowing authenticated users to download arbitrary content files regardless of their repository permissions. This vulnerability, rated Medium with a CVSS score of 4.3, arises from a weakness in how the system handles content uploads and data tickets, enabling users to craft dmr_content objects pointing to existing files. While there is no evidence of active exploitation in the wild and minimal community discussion, a public exploit (EDB-43005) exists, indicating the potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.3CPE matchmatch criteria | cpe:2.3:a:opentext:documentum_content_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.