Where
-Infinity
0

Vendor Risk Score

See how opentext compares to other vendors in security performance

View Risk Score →

Software

Severity
7.3
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Red

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

First published (updated )

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: always run deallocs on copy-on-write completion

Local fuzzing of 6.12.94 has found the following memory leak caused by doing 'copyfilerange()' within the same filesystem:

unreferenced object 0xffff88812192c980 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00 ................ c0 c5 92 21 81 88 ff ff 00 02 00 00 00 06 00 00 ...!............ backtrace (crc 7068d63f): kmemleakallocrecursive include/linux/kmemleak.h:42 [inline] slabpostallochook mm/slub.c:4152 [inline] slaballocnode mm/slub.c:4197 [inline] kmalloccachenoprof+0x168/0x2c0 mm/slub.c:4358 kmallocnoprof include/linux/slab.h:878 [inline] ocfs2findperslotfreelist fs/ocfs2/alloc.c:6618 [inline] ocfs2cacheblockdealloc+0x155/0x4b0 fs/ocfs2/alloc.c:6786 ocfs2cacheextentblockfree fs/ocfs2/alloc.c:6819 [inline] ocfs2unlinkpath+0x286/0x450 fs/ocfs2/alloc.c:2613 ocfs2rotatesubtreeleft fs/ocfs2/alloc.c:2779 [inline] ocfs2rotatetreeleft+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985 ocfs2rotatetreeleft+0x283/0xe00 fs/ocfs2/alloc.c:3237 ocfs2trytomergeextent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825 ocfs2splitextent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138 ocfs2clearextrefcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098 ocfs2replaceclusters fs/ocfs2/refcounttree.c:3131 [inline] ocfs2makeclusterswritable fs/ocfs2/refcounttree.c:3255 [inline] ocfs2replacecow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349 ocfs2refcountcowhunk fs/ocfs2/refcounttree.c:3427 [inline] ocfs2refcountcow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470 ocfs2prepareinodeforwrite fs/ocfs2/file.c:2340 [inline] ocfs2filewriteiter+0xbda/0x1880 fs/ocfs2/file.c:2451 iterfilesplicewrite+0x890/0xf60 fs/splice.c:743 dosplicefrom fs/splice.c:944 [inline] directspliceactor+0x232/0x480 fs/splice.c:1167 splicedirecttoactor+0x4b4/0xb60 fs/splice.c:1111 dosplicedirectactor fs/splice.c:1210 [inline] dosplicedirect+0x10f/0x1c0 fs/splice.c:1236 dosendfile+0x430/0xbf0 fs/readwrite.c:1388

unreferenced object 0xffff88812192c5c0 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 29 70 00 00 00 00 00 00 19 00 00 00 00 00 00 00 )p.............. backtrace (crc afec850f): kmemleakallocrecursive include/linux/kmemleak.h:42 [inline] slabpostallochook mm/slub.c:4152 [inline] slaballocnode mm/slub.c:4197 [inline] kmalloccachenoprof+0x168/0x2c0 mm/slub.c:4358 kmallocnoprof include/linux/slab.h:878 [inline] kzallocnoprof include/linux/slab.h:1014 [inline] ocfs2cacheblockdealloc+0x25c/0x4b0 fs/ocfs2/alloc.c:6793 ocfs2cacheextentblockfree fs/ocfs2/alloc.c:6819 [inline] ocfs2unlinkpath+0x286/0x450 fs/ocfs2/alloc.c:2613 ocfs2rotatesubtreeleft fs/ocfs2/alloc.c:2779 [inline] ocfs2rotatetreeleft+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985 ocfs2rotatetreeleft+0x283/0xe00 fs/ocfs2/alloc.c:3237 ocfs2trytomergeextent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825 ocfs2splitextent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138 ocfs2clearextrefcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098 ocfs2replaceclusters fs/ocfs2/refcounttree.c:3131 [inline] ocfs2makeclusterswritable fs/ocfs2/refcounttree.c:3255 [inline] ocfs2replacecow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349 ocfs2refcountcowhunk fs/ocfs2/refcounttree.c:3427 [inline] ocfs2refcountcow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470 ocfs2prepareinodeforwrite fs/ocfs2/file.c:2340 [inline] ocfs2filewriteiter+0xbda/0x1880 fs/ocfs2/file.c:2451 iterfilesplicewrite+0x890/0xf60 fs/splice.c:743 dosplicefrom fs/splice.c:9 ---truncated---

1 / 2
Source: MITRE
First published (updated )
Severity
7.3
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation.

This issue affects Opentext Directory Services: through 22.2.

First published (updated )
Severity
4.8
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS

First published (updated )
Severity
5.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

First published (updated )
Severity
6.9
Path Traversal
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:L/U:Amber

Path Traversal vulnerability discovered in OpenText™ CX-E Voice,

affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

First published (updated )
Severity
6.3
Path Traversal
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:L/U:Amber

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

First published (updated )
Severity
7.5
XSS
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

First published (updated )
Severity
6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.

First published (updated )
Severity
8.2
XSS
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS).

This issue affects Access Manager: from 5.1 through 5.1.2.

First published (updated )
Severity
6.1
EPSS
0.07%
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0.

First published (updated )
Severity
7.7
EPSS
0.04%
Infoleak
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices

First published (updated )
Severity
8.8
EPSS
0.04%
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Request

First published (updated )
Severity
7.4
EPSS
0.04%
CSRF
AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N

Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

First published (updated )
Severity
8.4
EPSS
0.04%
XSS
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N

Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.

First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.

First published (updated )
Severity
5.4
XSS
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download docbase or username parameter.

First published (updated )
Severity
5.4
XSS
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.

First published (updated )
Severity
8.8
Input Validation
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

OpenText Documentum Content Server allows superuser access via sysobjsave or save of a crafted object, followed by an unauthorized "UPDATE dmdbo.dmusers SET userprivileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532.

First published (updated )
Severity
8.8
SQL Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dmbptransition docbase method with a user-created dmprocedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.

First published (updated )
Severity
9.8
Input Validation
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.

First published (updated )
Severity
8.8
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and returntopresultsrowbased config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL commands via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2520.

First published (updated )
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.

First published (updated )
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.

First published (updated )
Severity
5
Weak Encryption
AV:N/AC:L/Au:N/C:P/I:N/A:N

OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.

First published (updated )
Severity
6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N

OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.

First published (updated )
Severity
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.

First published (updated )
Severity
5.1
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X, from 25.2.0 through 25.2.X, from 25.3.0 through 25.3.X.

Remedy

https://portal.microfocus.com/s/article/KM000045852?language=en_US
First published (updated )
Severity
5.1
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X.

Remedy

https://portal.microfocus.com/s/article/KM000045853?language=en_US
First published (updated )
Severity
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:X/U:X

Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.   The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X.

Remedy

https://portal.microfocus.com/s/article/KM000045854?language=en_US
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203