CVE-2022-45922
HIGHOpenText Extended ECM 21.1-22.1 - Improper Authentication via ll.KeepAliveSession Handler
Title source: llmDescription
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.
References (3)
Core 3
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/170615/OpenText-Extended-ECM-22.3-File-Deletion-LFI-Privilege-Escsalation.html
Exploit, Third Party Advisory
https://sec-consult.com/vulnerability-lab/advisory/multiple-post-authentication-vulnerabilities-including-rce-opentexttm-extended-ecm/
Exploit, Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2023/Jan/14
Scores
CVSS v3
8.8
EPSS
0.0160
EPSS Percentile
72.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (1)
opentext/opentext_extended_ecm
21.1 - 22.1
Published
Jan 18, 2023
Tracked Since
Feb 18, 2026