CVE-2024-12706: SQL Injection vulnerability discovered in OpenText™ Digital Asset Management.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T
he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database.
This issue affects Digital Asset Management.: through 24.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12706?
CVE-2024-12706 is considered a high severity vulnerability due to its potential to allow arbitrary SQL command execution.
How do I fix CVE-2024-12706?
To mitigate CVE-2024-12706, it is recommended to update OpenText Digital Asset Management to version 24.5 or later.
What systems are affected by CVE-2024-12706?
CVE-2024-12706 affects OpenText Digital Asset Management versions up to and including 24.4.
Who can exploit CVE-2024-12706?
CVE-2024-12706 can be exploited by authenticated users who have access to the OpenText Digital Asset Management system.
What type of vulnerability is CVE-2024-12706?
CVE-2024-12706 is classified as an SQL Injection vulnerability, which allows execution of arbitrary SQL commands.