CVE-2023-4552: Java Database Connectivity (JDBC) URL Manipulation
Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files.
An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its local file system.
This issue affects AppBuilder: from 21.2 before 23.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4552?
CVE-2023-4552 is classified as an improper input validation vulnerability that can be exploited by an authenticated user.
How do I fix CVE-2023-4552?
To remediate CVE-2023-4552, update OpenText AppBuilder to a patched version that addresses the input validation issue.
Who is affected by CVE-2023-4552?
CVE-2023-4552 affects authenticated users of OpenText AppBuilder on Windows and Linux who can manage databases.
What kind of exploit is possible with CVE-2023-4552?
Exploiting CVE-2023-4552 allows an authenticated user to access local files and potentially leverage the AppBuilder server.
Is CVE-2023-4552 a local or remote vulnerability?
CVE-2023-4552 is considered a local vulnerability as it requires authenticated access to the OpenText AppBuilder environment.