CVE-2017-5586: Opentext Documentum d2
Critical severity, CVSS 9.8. EPSS: 25.3% chance of exploitation in the next 30 days.
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
Affected products
- Opentext Documentum d2: version 4.0 only; version 4.1 only; version 4.2 only; version 4.3 only; version 4.4 only; version 4.5 only; …
Published 2017-02-22. Last modified 2026-06-17.