OpenText Content Management
cpe:2.3:a:opentext:opentext_extended_ecm:*:*:*:*:*:*:*
- >= 10, <= 24.4
A remote code execution vulnerability has been identified in OpenText Content Management (Extended ECM) versions 10.0 through 24.4, specifically within the WebReports module. This vulnerability arises from improper validation of input, allowing parameter injection. A user with the necessary OpenText Content Management privileges (excluding root) could exploit this vulnerability to execute arbitrary code on the target system.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users are advised to refer to OpenText Knowledge Base article KB0833739 or contact OpenText support through the My Support Portal to obtain the hotfix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.