CVE-2024-12862: REST API allows users without permissions to remove external collaborators
Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12862?
CVE-2024-12862 is classified as a high severity vulnerability due to incorrect authorization allowing unauthorized actions in the OpenText Content Server.
How do I fix CVE-2024-12862?
To fix CVE-2024-12862, ensure you update your OpenText Content Server to the latest version beyond 24.4.
What versions of OpenText Content Server are affected by CVE-2024-12862?
CVE-2024-12862 affects OpenText Content Server versions 20.2 through 24.4.
What kind of issue does CVE-2024-12862 represent?
CVE-2024-12862 represents an incorrect authorization vulnerability that allows users to remove external collaborators without proper permissions.
Is there a workaround for CVE-2024-12862?
Currently, there are no official workarounds for CVE-2024-12862, and updating to a fixed version is recommended.