Vulnerabilities (CVE)

Filtered by vendor Opentext Subscribe
Filtered by product Document Sciences Xpression
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14759 1 Opentext 1 Document Sciences Xpression 2017-10-11 7.5 HIGH 9.8 CRITICAL
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to an XML External Entity vulnerability: /xFramework/services/QuickDoc.QuickDocHttpSoap11Endpoint/. An unauthenticated user is able to read directory listings or system files, or cause SSRF or Denial of Service.