See how opentext compares to other vendors in security performance
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: always run deallocs on copy-on-write completion
Local fuzzing of 6.12.94 has found the following memory leak caused by doing 'copyfilerange()' within the same filesystem:
unreferenced object 0xffff88812192c980 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00 ................ c0 c5 92 21 81 88 ff ff 00 02 00 00 00 06 00 00 ...!............ backtrace (crc 7068d63f): kmemleakallocrecursive include/linux/kmemleak.h:42 [inline] slabpostallochook mm/slub.c:4152 [inline] slaballocnode mm/slub.c:4197 [inline] kmalloccachenoprof+0x168/0x2c0 mm/slub.c:4358 kmallocnoprof include/linux/slab.h:878 [inline] ocfs2findperslotfreelist fs/ocfs2/alloc.c:6618 [inline] ocfs2cacheblockdealloc+0x155/0x4b0 fs/ocfs2/alloc.c:6786 ocfs2cacheextentblockfree fs/ocfs2/alloc.c:6819 [inline] ocfs2unlinkpath+0x286/0x450 fs/ocfs2/alloc.c:2613 ocfs2rotatesubtreeleft fs/ocfs2/alloc.c:2779 [inline] ocfs2rotatetreeleft+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985 ocfs2rotatetreeleft+0x283/0xe00 fs/ocfs2/alloc.c:3237 ocfs2trytomergeextent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825 ocfs2splitextent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138 ocfs2clearextrefcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098 ocfs2replaceclusters fs/ocfs2/refcounttree.c:3131 [inline] ocfs2makeclusterswritable fs/ocfs2/refcounttree.c:3255 [inline] ocfs2replacecow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349 ocfs2refcountcowhunk fs/ocfs2/refcounttree.c:3427 [inline] ocfs2refcountcow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470 ocfs2prepareinodeforwrite fs/ocfs2/file.c:2340 [inline] ocfs2filewriteiter+0xbda/0x1880 fs/ocfs2/file.c:2451 iterfilesplicewrite+0x890/0xf60 fs/splice.c:743 dosplicefrom fs/splice.c:944 [inline] directspliceactor+0x232/0x480 fs/splice.c:1167 splicedirecttoactor+0x4b4/0xb60 fs/splice.c:1111 dosplicedirectactor fs/splice.c:1210 [inline] dosplicedirect+0x10f/0x1c0 fs/splice.c:1236 dosendfile+0x430/0xbf0 fs/readwrite.c:1388
unreferenced object 0xffff88812192c5c0 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 29 70 00 00 00 00 00 00 19 00 00 00 00 00 00 00 )p.............. backtrace (crc afec850f): kmemleakallocrecursive include/linux/kmemleak.h:42 [inline] slabpostallochook mm/slub.c:4152 [inline] slaballocnode mm/slub.c:4197 [inline] kmalloccachenoprof+0x168/0x2c0 mm/slub.c:4358 kmallocnoprof include/linux/slab.h:878 [inline] kzallocnoprof include/linux/slab.h:1014 [inline] ocfs2cacheblockdealloc+0x25c/0x4b0 fs/ocfs2/alloc.c:6793 ocfs2cacheextentblockfree fs/ocfs2/alloc.c:6819 [inline] ocfs2unlinkpath+0x286/0x450 fs/ocfs2/alloc.c:2613 ocfs2rotatesubtreeleft fs/ocfs2/alloc.c:2779 [inline] ocfs2rotatetreeleft+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985 ocfs2rotatetreeleft+0x283/0xe00 fs/ocfs2/alloc.c:3237 ocfs2trytomergeextent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825 ocfs2splitextent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138 ocfs2clearextrefcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098 ocfs2replaceclusters fs/ocfs2/refcounttree.c:3131 [inline] ocfs2makeclusterswritable fs/ocfs2/refcounttree.c:3255 [inline] ocfs2replacecow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349 ocfs2refcountcowhunk fs/ocfs2/refcounttree.c:3427 [inline] ocfs2refcountcow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470 ocfs2prepareinodeforwrite fs/ocfs2/file.c:2340 [inline] ocfs2filewriteiter+0xbda/0x1880 fs/ocfs2/file.c:2451 iterfilesplicewrite+0x890/0xf60 fs/splice.c:743 dosplicefrom fs/splice.c:9 ---truncated---
A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation.
This issue affects Opentext Directory Services: through 22.2.
Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.
Path Traversal vulnerability discovered in OpenText™ CX-E Voice,
affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.
Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS).
This issue affects Access Manager: from 5.1 through 5.1.2.
A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0.
Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices
Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Request
Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.
Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.
There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download docbase or username parameter.
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.
OpenText Documentum Content Server allows superuser access via sysobjsave or save of a crafted object, followed by an unauthorized "UPDATE dmdbo.dmusers SET userprivileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532.
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dmbptransition docbase method with a user-created dmprocedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and returntopresultsrowbased config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL commands via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2520.
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X, from 25.2.0 through 25.2.X, from 25.3.0 through 25.3.X.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X.
Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X.