CVE-2024-12862

MEDIUM

OpenText Content Server <24.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4.

References (1)

Core 1

Scores

CVSS v4 5.5
EPSS 0.0024
EPSS Percentile 14.8%
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
OpenText/Content Server 20.2-24.4
Published Apr 21, 2025
Tracked Since Feb 18, 2026