VYPR

Vendor CVEs

Opentext

All CVEs

244 total · sorted by risk
  • CVE-2021-22529MedAug 28, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1

  • CVE-2024-6358MedAug 6, 2024
    risk 0.41cvss 6.3epss 0.00

    Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

  • CVE-2024-6357MedAug 6, 2024
    risk 0.41cvss 6.3epss 0.00

    Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.

  • CVE-2020-25836MedJul 16, 2024
    risk 0.41cvss 6.3epss 0.00

    Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10.

  • CVE-2026-11878MedJun 24, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.

  • CVE-2026-3278MedMar 18, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions…

  • CVE-2025-12454MedMar 13, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue…

  • CVE-2025-12453MedMar 13, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue…

  • CVE-2025-8616MedAug 6, 2025
    risk 0.40cvss epss 0.00

    A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0.

  • CVE-2021-38134MedNov 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.

  • CVE-2021-38119MedNov 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2024-9841MedNov 8, 2024
    risk 0.40cvss 6.1epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

  • CVE-2021-38122MedAug 28, 2024
    risk 0.40cvss 6.2epss 0.00

    A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1

  • CVE-2018-20165MedMar 22, 2019
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.

  • CVE-2019-7416MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable.

  • CVE-2017-14756MedOct 3, 2017
    risk 0.40cvss 6.1epss 0.01

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (cat_id).

  • CVE-2017-14755MedOct 3, 2017
    risk 0.40cvss 6.1epss 0.01

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId.

  • CVE-2017-14525MedSep 28, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded…

  • CVE-2017-14524MedSep 28, 2017
    risk 0.40cvss 6.1epss 0.03

    Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded…

  • CVE-2017-8892MedMay 10, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image.

  • CVE-2025-8716MedSep 11, 2025
    risk 0.38cvss epss 0.00

    In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known.

  • CVE-2024-12543MedApr 21, 2025
    risk 0.38cvss epss 0.00

    User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.

  • CVE-2021-22518MedSep 12, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

  • CVE-2023-32264MedMar 8, 2024
    risk 0.38cvss 5.8epss 0.00

    CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer.

  • CVE-2025-8997MedAug 25, 2025
    risk 0.37cvss epss 0.00

    An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

  • CVE-2024-4556MedAug 28, 2024
    risk 0.37cvss 5.7epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects NetIQ Access Manager before 5.0.4 and before 5.1.

  • CVE-2024-3484MedMay 15, 2024
    risk 0.37cvss 5.7epss 0.01

    Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

  • CVE-2024-12863MedApr 21, 2025
    risk 0.36cvss epss 0.00

    Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.

  • CVE-2024-12862MedApr 21, 2025
    risk 0.36cvss epss 0.00

    Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4.

  • CVE-2021-38118MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2024-3488MedMay 15, 2024
    risk 0.36cvss 5.6epss 0.00

    File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

  • CVE-2023-4552MedJan 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its…

  • CVE-2025-9208MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is…

  • CVE-2025-13672MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered…

  • CVE-2024-8125MedFeb 4, 2025
    risk 0.35cvss epss 0.00

    Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection.  A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code…

  • CVE-2021-38131MedSep 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

  • CVE-2021-22503MedSep 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

  • CVE-2024-6361MedAug 5, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack.

  • CVE-2024-4187MedJul 31, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

  • CVE-2024-4429MedMay 28, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

  • CVE-2021-3010MedFeb 26, 2021
    risk 0.35cvss 5.4epss 0.01

    There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.

  • CVE-2020-13116MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation.

  • CVE-2018-7660MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter.

  • CVE-2018-7659MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.

  • CVE-2026-1658MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.  The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. …

  • CVE-2025-8055MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerability could allow an attacker to perform blind SSRF to other systems accessible from the XM Fax server. This issue affects XM Fax: 24.2.

  • CVE-2021-22501MedDec 19, 2024
    risk 0.34cvss epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation.  The vulnerability could be exploited to confidential information This issue affects Operations Bridge Manager: 2017.05, 2017.11,…

  • CVE-2023-32266MedOct 16, 2024
    risk 0.34cvss epss 0.00

    Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation.   This issue affects Application Lifecycle…

  • CVE-2021-38132MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

  • CVE-2024-3970MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.01

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

Page 4 of 5