OpenText Content Server
cpe:2.3:a:opentext:content_server:*:*:*:*:*:*:*
- >= 23.2, <= 25.1
A vulnerability has been identified in the OpenText Content Server REST API, affecting both Windows and Linux platforms. This incorrect authorization issue allows users without the necessary permissions to remove external collaborators. The vulnerability impacts OpenText Content Server versions 20.2 through 24.4.
Exploitation of this vulnerability could enable an authenticated user with a valid API token to delete external users from a node without having the appropriate permissions.
Hotfixes are available for the affected versions of OpenText Content Management for Engineering. This issue is resolved in version 25.2 and subsequent releases. For versions 23.2 to 24.4, hotfixes can be downloaded from the OpenText Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.