CVE-2022-45927

HIGH

Opentext Extended Ecm < 22.4 - IDOR

Title source: rule
STIX 2.1

Description

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects and execute arbitrary code.

Scores

CVSS v3 8.8
EPSS 0.0124
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
opentext/opentext_extended_ecm 20.4 - 22.4
Published Jan 18, 2023
Tracked Since Feb 18, 2026