OpenText Content Management Remote Code Execution Vulnerability in WebReports Module

Vulnerability

A remote code execution vulnerability has been identified in OpenText Content Management (Extended ECM) versions 10.0 through 24.4, specifically within the WebReports module. This vulnerability arises from improper validation of input, allowing parameter injection. A user with the necessary OpenText Content Management privileges (excluding root) could exploit this vulnerability to execute arbitrary code on the target system.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users are advised to refer to OpenText Knowledge Base article KB0833739 or contact OpenText support through the My Support Portal to obtain the hotfix.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
5.2
remediation
8.3
relevance
0.0
threat
0.0
urgency
5.7
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.