Vulnerabilidades em OpenText

148 resultados
Análise Vexday

Com 137 CVEs catalogadas, o portfólio de vulnerabilidades da OpenText apresenta uma taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem registros de falhas em exploração confirmada no momento. As 6 vulnerabilidades de severidade crítica e a ausência de provas de conceito públicas conhecidas reduzem, em parte, o risco imediato de exploração em larga escala. O tipo de falha mais recorrente é CWE-787 (escrita fora dos limites de memória), categoria que historicamente favorece execução remota de código e merece atenção prioritária em processos de patch management. A CVE mais relevante no momento, CVE-2021-31508, registra um EPSS de 0,0181, indicando baixa probabilidade estimada de exploração ativa no curto prazo, embora sua presença no radar recomende monitoramento contínuo.

CVE-2023-4501CRITICALAuthentication bypass in OpenText (Micro Focus) Enterprise ServerEPSS 0.8%CVE-2020-11862HIGHInsecure renegotiation in SSL protocol caused Denial of service attack in Privileged Account ManagerEPSS 0.7%CVE-2024-1148CRITICALWeak Access Control - Arbitrary file uploadEPSS 0.7%CVE-2024-1147CRITICALWeak Access Control - Arbitrary file downloadEPSS 0.7%CVE-2024-3968HIGHRemote Code Execution vulnerability in the iManagerEPSS 0.7%CVE-2023-32268HIGHAdministrator equivalent Filr user can access proxy administrator credentialsEPSS 0.7%CVE-2024-3967HIGHRemote Code Execution vulnerability in the iManagerEPSS 0.6%CVE-2022-26327MEDIUMStored cross-site scripting (XSS) has been discovered in OpenText™ Performance CenterEPSS 0.6%CVE-2021-38116HIGHPossible Command injection Vulnerability in OpenText iManagerEPSS 0.6%CVE-2023-7249MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows EPSS 0.6%CVE-2024-7050HIGHImproper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular sceEPSS 0.6%CVE-2024-1811CRITICALOpenText ArcSight Platform Remote VulnerabilityEPSS 0.6%CVE-2023-5913HIGHA potential Privilege Escalation vulnerability in opentext Fortify ScanCentral DAST API.EPSS 0.6%CVE-2023-24466HIGHPossible XML External Entity Injection in OpenText iManagerEPSS 0.5%CVE-2021-38120MEDIUMRemote Code Execution using Bash command Injection in backup scheduling functionality in NetIQ Advance AuthenticationEPSS 0.5%CVE-2024-0967MEDIUMOpenText / Micro Focus ArcSight Enterprise Security Manager Remote VulnerabilityEPSS 0.5%CVE-2024-3970MEDIUMServer-Side Request Forgery vulnerability in iManagerEPSS 0.5%CVE-2023-6123HIGHImproper Neutralization vulnerability affects OpenText ALM Octane.EPSS 0.5%CVE-2024-3484MEDIUMPath Traversal vulnerability found in iManagerEPSS 0.5%CVE-2024-3969HIGH XML External Entity injection vulnerability in iManagerEPSS 0.5%