First published: Wed May 07 2025(Updated: )
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allow authenticated users to change their password without providing their old password. This issue affects Operations Bridge Manager: 24.2, 24.4.
Credit: security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenText Operations Bridge Manager | >=24.2<=24.4 |
https://portal.microfocus.com/s/article/KM000040405
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3272 is classified as a high severity vulnerability due to its potential impact on authentication and user access control.
To mitigate CVE-2025-3272, upgrade to a patched version of OpenText Operations Bridge Manager that resolves this password change issue.
CVE-2025-3272 affects users of OpenText Operations Bridge Manager versions 24.2 and 24.4.
CVE-2025-3272 is an Incorrect Authorization vulnerability that allows users to change passwords without verification.
Yes, authenticated users can exploit CVE-2025-3272 to change their passwords without needing their old passwords, potentially compromising accounts.