PT-2024-17018 · Opentext · Opentext Pvcs Version Manager

Redblaze

·

Published

2024-03-21

·

Updated

2024-03-23

·

CVE-2024-1147

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText PVCS Version Manager versions prior to 8.6.3.3
Description The issue is related to weak access control in OpenText PVCS Version Manager, which allows potential bypassing of authentication and download of files. This could lead to unauthorized access to sensitive data.
Recommendations For versions prior to 8.6.3.3, update to version 8.6.3.3 as soon as possible to prevent remote attacks.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-1147

Affected Products

Opentext Pvcs Version Manager