ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Expert found critical flaws in OpenText ECM System

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-45926
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.

NVD description · AI analysis pending
8.8
group max
17% PoC ×3
  • opentext opentext extended ecm
Full article191 words · extracted from securityaffairs.com · click to collapse

The OpenText enterprise content management (ECM) system is affected by multiple vulnerabilities, including a critical RCE.

Armin Stock (Atos), researcher at cybersecurity firm Sec Consult, discovered multiple vulnerabilities in the OpenText enterprise content management (ECM) product.

OpenText Extended ECM is an enterprise CMS platform that manages the information lifecycle by integrating with leading enterprise applications, such as SAP, Microsoft 365, Salesforce and SAP SuccessFactors.

The list of vulnerabilities discovered by the experts includes:

The advisories for the high-severity vulnerabilities includes Proof-of-concept (PoC) code.

The expert reported the issues to OpenText in October 2022 which addressed it this month with the release of version 22.4.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, ECM)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/141157/security/opentext-critical-flaws.html