Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
The vulnerability (CWE-918 / argument injection) occurs in the module responsible for document processing. An attacker can submit a crafted request to the service without needing to possess any credentials by injecting malicious arguments into process calls or system commands executed during document transformation. As a result, arbitrary code execution in the context of the service process is possible.
An unauthenticated attacker can take full control of the system on which the service is running — gaining the ability to read and modify data as well as disrupt system operations. The compromise affects only the directly vulnerable component (SC:N in the CVSS vector).
Patches available from the vendor should be applied in accordance with the references — detailed information about versions containing fixes was published in the official Hyland security bulletin at the address indicated in the references (connect.hyland.com).
Hyland Alfresco Transform Service and Hyland Alfresco Transform Core — versions indicated in the vendor's references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHyland Alfresco Transform Core
APPHyland< 5.2.4Hyland Alfresco Transform Service
APPHyland< 4.2.3
Related vulnerabilities
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read an...
Hyland Alfresco Transformation Service umożliwia nieuwierzytelnionym atakującym przeprowadzenie SSRF poprzez f...
PACSgear PACS Scan 5.2.1 — nieuwierzytelniony RCE przez .NET Remoting
PACSgear MediaWriter — nieuwierzytelniony RCE przez .NET Remoting TCP
SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji