VYPR

Documentum D2

by Opentext

CVEs (4)

  • CVE-2017-5586CriFeb 22, 2017
    risk 0.69cvss 9.8epss 0.25

    OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.

  • CVE-2023-32264MedMar 8, 2024
    risk 0.38cvss 5.8epss 0.00

    CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer.

  • CVE-2018-7660MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter.

  • CVE-2018-7659MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.