CVE-2019-25257
Published: 12/24/2025 20:15:54
LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
MEDIUM
CVSS v3: 6.5
CVSS v3: 6.5
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 0.0.0.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 25.4 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 25.3 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 25.2 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 25.1.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 25.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 24.4 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 24.4.0 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 24.3 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 24.2.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 24.2 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 24.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 23.3 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 23.2.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 23.2 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 23.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 22.4 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 22.3 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 22.2 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 22.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.11.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.11 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.8.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.8 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.5.1 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.5.0 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 21.2.0 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.20 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.19.3667 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.18.3599 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.17 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.16.3445 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.15.3368 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.14.3263 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.13.3179 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.12.3054 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.11.3040 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.11.2990 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.10.2934 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.9.2878 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
| 11.4.8.2822 | tesseract (3.02.02) | Not Affected | Code Not Present | LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself. |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
NONE
Base Score
6.5
Base Severity
MEDIUM
Confidentiality Impact
HIGH
Integrity Impact
NONE
Privileges Required
LOW
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Version
3.1