CVE-2024-10864: SQL Injection vulnerability has been discovered in OpenText™ Advanced Authentication.
Published May 14, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5
Affected Software
1 affected component
OpenText Advanced Authentication<6.5
Event History
May 14, 2025
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10864?
The severity of CVE-2024-10864 is considered high due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-10864?
To fix CVE-2024-10864, upgrade OpenText Advanced Authentication to version 6.5 or later.
3
What products are affected by CVE-2024-10864?
CVE-2024-10864 affects OpenText Advanced Authentication versions prior to 6.5.
4
What type of vulnerability is CVE-2024-10864?
CVE-2024-10864 is an SQL Injection vulnerability caused by improper neutralization of special elements used in SQL commands.
5
Can CVE-2024-10864 be exploited remotely?
Yes, CVE-2024-10864 can potentially be exploited remotely by attackers targeting the SQL commands.