CVE-2024-10863: Client-side audit exclusion vulnerability

Published Nov 22, 2024
·
Updated

: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4.

End-users can potentially exploit the vulnerability to exclude audit trails from being recorded on the client side.

Affected Software

1 affected component
OpenText Secure Content Manager>10.1, <24.4

Remediation

Information

Audit trails will be captured on the server side instead of the client side, thereby eliminating the vulnerability and its impact Apply the following patch builds in your data center. Secure Content Manager 24.3 Patch 1: Patch 219146 - Content Manager 24.3 Patch 1 Build 86 Secure Content Manager 24.2 Patch 1: Patch 219145 - Content Manager 24.2 Patch 1 Build 123 Secure Content Manager 23.4 Patch 2: Patch 1593502 - Content Manager 23.4 Patch 2 Build 240 Secure Content Manager 10.1 Patch 6: Patch 1593711 – Content Manager 10.1 Patch 6 Build 1185

Event History

Nov 22, 2024
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-10863?

CVE-2024-10863 has been classified as a moderate severity vulnerability due to its potential for Audit Log Manipulation.

2

How do I fix CVE-2024-10863?

To mitigate CVE-2024-10863, upgrade OpenText Secure Content Manager to version 24.4 or later.

3

What versions of OpenText Secure Content Manager are affected by CVE-2024-10863?

CVE-2024-10863 affects OpenText Secure Content Manager versions from 10.1 up to but not including 24.4.

4

What type of vulnerability is CVE-2024-10863?

CVE-2024-10863 is an Insufficient Logging vulnerability that allows for potential Audit Log Manipulation.

5

Can end-users exploit CVE-2024-10863?

Yes, end-users can potentially exploit CVE-2024-10863 to exclude important audit trails from being recorded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203