CVE-2024-10923: Improper Neutralization vulnerability has been discovered in OpenText™ ALM Octane Management.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack.
This issue affects ALM Octane Management: from 16.2.100 through 24.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10923?
CVE-2024-10923 has a high severity due to its potential for Remote Code Execution through Stored XSS.
How do I fix CVE-2024-10923?
To mitigate CVE-2024-10923, update OpenText ALM Octane Management to version 24.4 or later.
What type of vulnerability is CVE-2024-10923?
CVE-2024-10923 is classified as an Improper Neutralization of Input during Web Page Generation, leading to Cross-site Scripting (XSS).
Which versions of ALM Octane Management are affected by CVE-2024-10923?
CVE-2024-10923 affects ALM Octane Management versions from 16.2.100 to 24.4.
Can CVE-2024-10923 result in data breaches?
Yes, CVE-2024-10923 could potentially lead to data breaches through exploitation of the Stored XSS vulnerability.