PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5586 Opentext CVE debrief

CVE-2017-5586 is a critical remote command execution issue in OpenText Documentum D2 4.x. According to the official record, a remote attacker can execute arbitrary commands by sending a crafted serialized Java object, with references to BeanShell and Apache Commons Collections libraries. Because the issue is network-reachable, requires no privileges, and needs no user interaction, exposed D2 instances should be treated as high-risk assets.

Vendor
Opentext
Product
Documentum D2
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-22
Original CVE updated
2026-05-13
Advisory published
2017-02-22
Advisory updated
2026-05-13

Who should care

Security teams, application owners, platform administrators, and incident responders responsible for OpenText Documentum D2 deployments, especially versions 4.0 through 4.6 and any internet-facing or broadly reachable instances.

Technical summary

The official NVD record maps this issue to OpenText Documentum D2 versions 4.0 through 4.6 and assigns CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The description states that remote attackers can execute arbitrary commands via a crafted serialized Java object, with the issue related to BeanShell (bsh) and Apache Commons Collections (ACC) libraries. NVD lists CWE-20. Defensively, this should be treated as a likely unsafe input-handling/deserialization path in a Java application surface, with full compromise potential if reachable.

Defensive priority

Immediate and critical. This is a network exploitable issue with no authentication or user interaction required and full confidentiality, integrity, and availability impact in the published CVSS vector. Prioritize any exposed Documentum D2 4.x instance, especially externally reachable deployments, for urgent remediation or isolation.

Recommended defensive actions

  • Inventory all OpenText Documentum D2 deployments and confirm whether any instance is running versions 4.0 through 4.6.
  • Treat internet-facing or otherwise reachable D2 systems as emergency remediation targets.
  • Restrict network access to D2 to trusted administrative or application paths only until remediation is complete.
  • Follow the applicable OpenText remediation guidance for affected D2 versions and apply the vendor fix or upgrade path when available.
  • Monitor logs and surrounding telemetry for signs of unexpected command execution, unusual process launches, or suspicious Java serialization activity.
  • If immediate remediation is not possible, isolate affected systems and reduce exposure with compensating controls such as strict allowlisting and segmentation.
  • Validate whether any connected credentials, application secrets, or host-level access may have been exposed and rotate them if compromise is suspected.

Evidence notes

This debrief is based on the official CVE/NVD record supplied in the corpus. The NVD entry lists the vulnerable product as OpenText Documentum D2 4.0 through 4.6, CVSS 3.0 9.8, and CWE-20. The supplied references also include third-party exploit/advisory links (Packet Storm, Exploit-DB, SecurityFocus) that provide additional context, but they should be treated as contextual references rather than proof of exploitation in any specific environment. No KEV listing was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5586 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5586

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5586 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5586

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.