OpenText Content Management User Enumeration and Data Integrity Vulnerability in Barcode Functionality
Vulnerability
A vulnerability allowing user enumeration and data integrity issues in barcode functionality has been identified in OpenText Content Management versions 24.3 prior to 25.1, as well as in versions 20.2 through 24.4. This vulnerability allows a malicious authenticated attacker to potentially alter barcode attributes.
Impact
Exploitation of this vulnerability could lead to unauthorized changes in barcode attributes, allowing for manipulation of barcode data.
Remediation
Hotfixes are available for affected versions of OpenText Content Management. Instructions for applying the hotfix can be found in the OpenText Knowledge Base articles KB0829343, KB0829342, KB0829344, KB0829346, KB0829350, KB0829348, KB0829347, KB0829349, KB0829355, KB0829352, KB0829354, KB0829357, KB0829356, KB0829964, and KB0829965.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
