We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-8125

A remote code vulnerability has been discovered in OpenText™ Content Management.



Description

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection.  A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system. This issue affects Content Management (Extended ECM): from 10.0 through 24.4  with WebReports module installed and enabled.

Reserved 2024-08-23 | Published 2025-02-04 | Updated 2025-02-04 | Assigner OpenText


MEDIUM: 5.4CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/S:P/AU:N/R:U/V:C/RE:H/U:Amber

Problem types

CWE-1287 Improper Validation of Specified Type of Input

Product status

Default status
unaffected

10.0
affected

References

support.opentext.com/...henticated&sysparm_article=KB0834058

cve.org (CVE-2024-8125)

nvd.nist.gov (CVE-2024-8125)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-8125

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.