S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 11, 2024

CVE-2017-14524 Scanner

Detects 'Open Redirect' vulnerability in OpenText Documentum Administrator affects v. 7.2.0180.0055.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-14524
6.1
CVSS

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

OpenText Documentum Administrator is an enterprise content management system that is used to manage, secure, and share large volumes of electronic documents and content. This product is mainly used in organizations that require controlled access to sensitive data, such as healthcare, legal, and financial institutions. It provides a centralized platform for managing and securing documents, streamlining business processes and collaboration, and ensuring compliance with regulatory standards. 

One of the vulnerabilities detected in this product is CVE-2017-14524. This vulnerability allows remote attackers to conduct phishing attacks and redirect users to arbitrary web sites by exploiting multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055. These vulnerabilities can be triggered by passing a URL in the startat parameter to xda/help/en/default.htm or by using /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect. 

If exploited, CVE-2017-14524 can result in unauthorized access to sensitive data, such as login credentials, financial information, and personal identification data. Attackers can use these unauthorized access points to launch further attacks, such as malware installation, data theft, or ransomware attacks. Phishing attacks can be particularly damaging, since they trick users into revealing sensitive information or downloading malicious software, compromising the entire organization’s network and data security. 

In conclusion, s4e.io’s platform offers a wealth of resources for anyone concerned about protecting their digital assets from vulnerabilities like CVE-2017-14524. By leveraging the pro features of this platform, users can stay informed about emerging threats, secure their network and data assets, and outpace attackers with a proactive approach to cyber security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions: 

  • Update OpenText Documentum Administrator to the latest patched version to address these vulnerabilities 
  • Install and maintain updated antivirus and firewall software 
  • Educate users on how to avoid clicking on suspicious links and how to report suspected phishing attacks 
  • Monitor network traffic for unusual activity, such as outgoing connections to suspicious domains or IP addresses 
  • Configure OpenText Documentum Administrator to restrict access to sensitive data and enforce strong access controls 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-14524 scanner - Open Redirect vulnerability in OpenText Documentum Administrator | S4E