VYPR
Unrated severityNVD Advisory· Published Jun 15, 2021· Updated Aug 3, 2024

CVE-2021-31498

CVE-2021-31498

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-12744.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read in OpenText Brava! Desktop's DWF parsing allows remote attackers to disclose sensitive information via a crafted file.

Vulnerability

This vulnerability resides in the parsing of DWF files by OpenText Brava! Desktop version 16.6.3.84. The specific flaw is a lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. This out-of-bounds read occurs when the application processes a specially crafted DWF file [1].

Exploitation

An attacker must convince a user to visit a malicious web page or open a malicious DWF file. No authentication or special network position is required; the attack is remote but relies on user interaction. The attacker crafts a DWF file that triggers the out-of-bounds read when parsed by the vulnerable Brava! Desktop installation [1].

Impact

Successful exploitation leads to information disclosure of sensitive data from the process memory. The CVSS score is 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N), indicating low severity with limited confidentiality impact. The advisory notes that an attacker could leverage this vulnerability in conjunction with other flaws to achieve arbitrary code execution in the context of the current process [1].

Mitigation

As of the advisory publication date (June 2021), no official fix has been released by OpenText. The ZDI advisory indicates the vendor was notified but did not provide a patch [1]. Users should exercise caution when opening DWF files from untrusted sources and consider using alternative software until a fix is available.

References
  1. ZDI-21-638

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.