CVE-2023-32266

MEDIUM

OpenText ALM,QC <16.0 - Code Injection

Title source: llm
STIX 2.1

Description

Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation.   This issue affects Application Lifecycle Management (ALM),Quality Center: 15.00, 15.01, 15.01 P1, 15.01 P2, 15.01 P3, 15.01 P4, 15.01 P5, 15.51, 15.51 P1, 15.51 P2, 15.51 P3, 16.00, 16.01 P1.

Scores

CVSS v4 5.3
EPSS 0.0008
EPSS Percentile 22.5%
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/V:D/RE:L/U:Clear

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (13)
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.00
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.01
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.01 P1
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.01 P2
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.01 P3
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.01 P4
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.01 P5
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.51
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.51 P1
OpenText™/Application Lifecycle Management (ALM),Quality Center 15.51 P2
... and 3 more
Published Oct 16, 2024
Tracked Since Feb 18, 2026