PT-2025-3688 · Opentext · Opentext Solutions Business Manager

Wiktoria Lewandowska

·

Published

2025-01-15

·

Updated

2025-01-15

·

CVE-2024-7085

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/S:N/AU:N/R:A/V:C/RE:M/U:Red
Name of the Vulnerable Software and Affected Versions OpenText Solutions Business Manager (SBM) versions prior to 12.2.1
Description The issue is related to improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS). This could lead to the exposure of private information to an unauthorized actor. The vulnerability allows for Stored XSS.
Recommendations For versions prior to 12.2.1, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7085

Affected Products

Opentext Solutions Business Manager