CVE-2022-45927

HIGH

OpenText Extended ECM 20.4-22.3 - Unauthenticated Remote Code Execution via QDS Endpoint

Title source: llm
STIX 2.1

Description

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects and execute arbitrary code.

Scores

CVSS v3 8.8
EPSS 0.0187
EPSS Percentile 76.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
opentext/opentext_extended_ecm 20.4 - 22.4
Published Jan 18, 2023
Tracked Since Feb 18, 2026