PT-2024-13247 · Opentext · Opentext Appbuilder

George Mathias

·

Published

2024-01-29

·

Updated

2024-02-05

·

CVE-2023-4551

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText AppBuilder versions 21.2 through 23.2
Description The issue is related to improper input validation in the OpenText AppBuilder's Scheduler functionality, which allows authenticated users to inject arbitrary operating system commands into the executing process. This enables OS Command Injection.
Recommendations For versions 21.2 through 23.2, update to version 23.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Scheduler functionality to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-4551

Affected Products

Opentext Appbuilder