CVE-2023-4552

MEDIUM

OpenText AppBuilder <23.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its local file system. This issue affects AppBuilder: from 21.2 before 23.2.

Scores

CVSS v3 5.5
EPSS 0.0037
EPSS Percentile 28.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
opentext/appbuilder 21.2 - 23.2
Published Jan 29, 2024
Tracked Since Feb 18, 2026