CVE-2022-45922: High severity opentext extended ecm vulnerability
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45922?
CVE-2022-45922 has been categorized as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2022-45922?
To mitigate CVE-2022-45922, ensure that the Web Admin password is validated correctly and that only authenticated sessions can create AdminPwd cookies.
What versions of OpenText are affected by CVE-2022-45922?
CVE-2022-45922 affects OpenText Content Suite Platform versions between 21.1 and 22.1.
What type of issue is described in CVE-2022-45922?
CVE-2022-45922 describes an authentication bypass vulnerability that allows unauthorized access to administrative endpoints.
Can CVE-2022-45922 lead to further attacks?
Yes, CVE-2022-45922 can potentially be exploited to gain escalated privileges, leading to additional attacks on the system.