VYPR

Vendor CVEs

Opentext

All CVEs

244 total · sorted by risk
  • CVE-2024-3485MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

  • CVE-2023-4553MedJan 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects AppBuilder: from 21.2 before 23.2.

  • CVE-2024-10863MedNov 22, 2024
    risk 0.33cvss epss 0.00

    : Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4. End-users can potentially exploit the vulnerability to exclude audit trails from being recorded…

  • CVE-2021-38120MedAug 28, 2024
    risk 0.33cvss 5.1epss 0.01

    A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.

  • CVE-2022-26327MedAug 21, 2024
    risk 0.33cvss epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63.

  • CVE-2023-7248MedMar 15, 2024
    risk 0.33cvss 5.0epss 0.00

    Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.  The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the…

  • CVE-2022-26322MedSep 12, 2024
    risk 0.32cvss 4.9epss 0.00

    Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200.

  • CVE-2023-4554MedJan 29, 2024
    risk 0.32cvss 4.9epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor is vulnerable to XML External Entity Processing (XXE), allowing an authenticated user…

  • CVE-2024-5532MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the…

  • CVE-2024-7428MedAug 23, 2024
    risk 0.31cvss epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenText™ Network Node Manager i (NNMi) allows URL Redirector Abuse.This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.

  • CVE-2024-7427MedAug 23, 2024
    risk 0.31cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Network Node Manager i (NNMi) could allow Cross-Site Scripting (XSS).This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.

  • CVE-2023-38535MedMar 13, 2024
    risk 0.31cvss 4.7epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.  

  • CVE-2017-15014MedOct 13, 2017
    risk 0.31cvss 4.3epss 0.05

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an authenticated user uploads…

  • CVE-2024-0967MedMar 1, 2024
    risk 0.28cvss 4.3epss 0.01

    A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

  • CVE-2024-3487LowMay 15, 2024
    risk 0.23cvss 3.5epss 0.00

    Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.

  • CVE-2021-31506LowJun 29, 2021
    risk 0.22cvss 3.3epss 0.01

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

  • CVE-2021-31501LowJun 15, 2021
    risk 0.22cvss 3.3epss 0.01

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2021-31498LowJun 15, 2021
    risk 0.22cvss 3.3epss 0.01

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2024-4692LowOct 16, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in…

  • CVE-2024-4211LowOct 16, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText…

  • CVE-2025-11884LowNov 19, 2025
    risk 0.15cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The vulnerability could allow an attacker has high level access to UCMDB to create or update data with malicious scripts This issue…

  • CVE-2025-2517LowApr 21, 2025
    risk 0.15cvss epss 0.00

    Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.

  • CVE-2025-2236LowMay 27, 2025
    risk 0.14cvss epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue…

  • CVE-2024-12706LowApr 28, 2025
    risk 0.14cvss epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects…

  • CVE-2025-0883LowMar 12, 2025
    risk 0.14cvss epss 0.00

    Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager.  The vulnerability could reveal sensitive information retained by the browser. This issue affects Service Manager: 9.70, 9.71, 9.72, 9.80.

  • CVE-2022-26328LowAug 21, 2024
    risk 0.13cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63.

  • CVE-2025-0885LowJul 3, 2025
    risk 0.12cvss epss 0.00

    Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow unauthorized access to calendar items marked private. This issue affects GroupWise versions 7 through 17.5,…

  • CVE-2004-2496Dec 31, 2004
    risk 0.04cvss epss 0.09

    The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.

  • CVE-2003-1173Dec 31, 2003
    risk 0.03cvss epss 0.03

    Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.

  • CVE-2011-1741Jul 19, 2011
    risk 0.01cvss epss 0.08

    Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP.

  • CVE-2015-6867Nov 4, 2015
    risk 0.00cvss epss 0.05

    The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914.

  • CVE-2015-6530Aug 20, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboard.jsp.

  • CVE-2013-6994May 19, 2014
    risk 0.00cvss epss 0.01

    OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.

  • CVE-2013-6807May 19, 2014
    risk 0.00cvss epss 0.01

    The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.

  • CVE-2013-6806May 19, 2014
    risk 0.00cvss epss 0.01

    OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.

  • CVE-2013-6805May 19, 2014
    risk 0.00cvss epss 0.01

    OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.

  • CVE-2013-3243Oct 28, 2013
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in OpenText/IXOS ECM for SAP NetWeaver allows remote attackers to execute arbitrary ABAP code via unknown vectors.

  • CVE-2010-5283Nov 26, 2012
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder and resource permissions.

  • CVE-2010-5282Nov 26, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx,…

  • CVE-2008-0769Feb 14, 2008
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input.

  • CVE-2007-2976Jun 1, 2007
    risk 0.00cvss epss 0.01

    Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown;…

  • CVE-2005-1045May 2, 2005
    risk 0.00cvss epss 0.02

    OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.

  • CVE-2004-0037Jan 20, 2004
    risk 0.00cvss epss 0.02

    FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.

  • CVE-2001-0631Aug 22, 2001
    risk 0.00cvss epss 0.01

    Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.

Page 5 of 5