PT-2024-12038 · Opentext · Opentext Imanager

Published

2024-11-22

·

Updated

2024-11-22

·

CVE-2023-24467

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText iManager version 3.2.6.0000
Description A possible command injection issue has been discovered in the iManager GET parameter of OpenText iManager.
Recommendations For OpenText iManager version 3.2.6.0000, consider restricting access to the iManager GET parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-24467

Affected Products

Opentext Imanager