CVE-2019-25257

Published: 12/24/2025 20:15:54
LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
MEDIUM
CVSS v3: 6.5

Status

DocFilters Release Package State Justification Comment
0.0.0.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
25.4 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
25.3 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
25.2 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
25.1.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
25.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
24.4 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
24.4.0 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
24.3 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
24.2.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
24.2 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
24.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
23.3 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
23.2.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
23.2 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
23.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
22.4 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
22.3 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
22.2 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
22.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.11.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.11 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.8.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.8 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.5.1 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.5.0 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
21.2.0 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.20 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.19.3667 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.18.3599 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.17 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.16.3445 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.15.3368 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.14.3263 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.13.3179 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.12.3054 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.11.3040 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.11.2990 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.10.2934 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.9.2878 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.
11.4.8.2822 tesseract (3.02.02) Not Affected Code Not Present LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC’s document management server application. The vulnerability is in LogicalDOC’s configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
NONE
Base Score
6.5
Base Severity
MEDIUM
Confidentiality Impact
HIGH
Integrity Impact
NONE
Privileges Required
LOW
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Version
3.1

References