CVE-2017-14525
Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2)…
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- opentext/documentum administrator · opentext/documentum webtop
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Sep/57Issue Tracking, Mailing List, Third Party Advisory
- https://knowledge.opentext.com/knowledge/llisapi.dll/Open/68982774Permissions Required, Vendor Advisory
- http://seclists.org/fulldisclosure/2017/Sep/57Issue Tracking, Mailing List, Third Party Advisory
- https://knowledge.opentext.com/knowledge/llisapi.dll/Open/68982774Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.