CVE-2022-35898: Critical severity opentext bizmanager vulnerability
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35898?
CVE-2022-35898 is considered a high-severity vulnerability due to the potential for unauthorized password changes affecting user accounts, including administrative access.
How do I fix CVE-2022-35898?
To fix CVE-2022-35898, upgrade OpenText BizManager to version 16.6.0.1 or later, which includes proper validation during the change-password operation.
Who is affected by CVE-2022-35898?
All authenticated users of OpenText BizManager versions below 16.6.0.1 are affected by CVE-2022-35898.
What type of vulnerability is CVE-2022-35898?
CVE-2022-35898 is an authentication vulnerability that allows users to change the passwords of other users without proper validation.
Is there a potential risk from CVE-2022-35898?
Yes, CVE-2022-35898 poses a significant risk as it allows unauthorized password changes, leading to potential account takeovers and data breaches.