PT-2023-13451 · Opentext · Opentext Imanager

CVE-2022-35898

·

Publicado

2023-05-01

·

Atualizado

2025-01-30

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText BizManager versions prior to 16.6.0.1
Description The issue arises from improper validation during the change-password operation, allowing any authenticated user to change the password of any other user, including the Administrator account.
Recommendations For versions prior to 16.6.0.1, update to version 16.6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the change-password operation to minimize the risk of exploitation.

Correção

Improper Authentication

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-35898

Produtos afetados

Opentext Imanager