CVE-2025-3272: Incorrect user authorization vulnerability has been identified in Open Text Operations Bridge Manager.
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.
The vulnerability could allow authenticated users to change their password without providing their old password.
This issue affects Operations Bridge Manager: 24.2, 24.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3272?
CVE-2025-3272 is classified as a high severity vulnerability due to its potential impact on authentication and user access control.
How do I fix CVE-2025-3272?
To mitigate CVE-2025-3272, upgrade to a patched version of OpenText Operations Bridge Manager that resolves this password change issue.
Who is affected by CVE-2025-3272?
CVE-2025-3272 affects users of OpenText Operations Bridge Manager versions 24.2 and 24.4.
What type of vulnerability is CVE-2025-3272?
CVE-2025-3272 is an Incorrect Authorization vulnerability that allows users to change passwords without verification.
Can authenticated users exploit CVE-2025-3272?
Yes, authenticated users can exploit CVE-2025-3272 to change their passwords without needing their old passwords, potentially compromising accounts.