PT-2023-13451 · Opentext · Opentext Imanager

Published

2023-05-01

·

Updated

2025-01-30

·

CVE-2022-35898

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText BizManager versions prior to 16.6.0.1
Description The issue arises from improper validation during the change-password operation, allowing any authenticated user to change the password of any other user, including the Administrator account.
Recommendations For versions prior to 16.6.0.1, update to version 16.6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the change-password operation to minimize the risk of exploitation.

Fix

Improper Authentication

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2022-35898

Affected Products

Opentext Imanager