CVE-2022-35898

CRITICAL

OpenText BizManager <16.6.0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0064
EPSS Percentile 45.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-295 CWE-287
Status published
Products (1)
opentext/bizmanager < 16.6.0.1
Published May 01, 2023
Tracked Since Feb 18, 2026