PT-2025-21167 · Opentext · Opentext Advance Authentication

Published

2025-05-14

·

Updated

2025-05-15

·

CVE-2024-10865

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:N/U:Amber
Name of the Vulnerable Software and Affected Versions: OpenText Advance Authentication versions prior to 6.5
Description: The issue is related to improper input validation, which leads to a Cross-site Scripting (XSS) vulnerability. This type of vulnerability allows attackers to inject malicious scripts into websites, potentially leading to unauthorized access or control.
Recommendations: For versions prior to 6.5, update to version 6.5 or later to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10865

Affected Products

Opentext Advance Authentication