Vulnerabilities > Opentext > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2023-7249 Path Traversal vulnerability in Opentext Directory Services
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.
network
low complexity
opentext CWE-22
critical
9.8
2024-08-06 CVE-2024-6359 Unspecified vulnerability in Opentext Arcsight Intelligence
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
network
low complexity
opentext
critical
9.8
2024-03-15 CVE-2023-7248 Unspecified vulnerability in Opentext Vertica
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.  The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences.
network
low complexity
opentext
critical
9.8
2023-05-01 CVE-2022-35898 Improper Authentication vulnerability in Opentext Bizmanager
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.
network
low complexity
opentext CWE-287
critical
9.8
2017-10-03 CVE-2017-14759 XXE vulnerability in Opentext Document Sciences Xpression 4.5
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to an XML External Entity vulnerability: /xFramework/services/QuickDoc.QuickDocHttpSoap11Endpoint/.
network
low complexity
opentext CWE-611
critical
9.8
2017-02-22 CVE-2017-5586 Improper Input Validation vulnerability in Opentext Documentum D2
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
network
low complexity
opentext CWE-20
critical
9.8