PT-2023-13451 · Opentext · Opentext Imanager
Published
2023-05-01
·
Updated
2025-01-30
·
CVE-2022-35898
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenText BizManager versions prior to 16.6.0.1
Description
The issue arises from improper validation during the change-password operation, allowing any authenticated user to change the password of any other user, including the Administrator account.
Recommendations
For versions prior to 16.6.0.1, update to version 16.6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the change-password operation to minimize the risk of exploitation.
Fix
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opentext Imanager