CVE-2013-6806

OpenText Exceed OnDemand 8 - Man-in-the-Middle Authentication Downgrade via Crafted Response

Title source: llm
STIX 2.1

Description

OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.

References (1)

Core 1
Core References

Scores

EPSS 0.0103
EPSS Percentile 59.2%

Details

CWE
CWE-287
Status published
Products (1)
opentext/exceed_ondemand 8.0
Published May 19, 2014
Tracked Since Feb 18, 2026