CVE-2023-4550

HIGH

OpenText AppBuilder <23.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted. This issue affects AppBuilder: from 21.2 before 23.2.

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 22.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-552 CWE-20
Status published
Products (1)
opentext/appbuilder 21.2 - 23.2
Published Jan 29, 2024
Tracked Since Feb 18, 2026