Home

Description

User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.

PUBLISHED Reserved 2024-12-11 | Published 2025-04-21 | Updated 2025-04-21 | Assigner OpenText




MEDIUM: 5.9CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-841: Improper Enforcement of Behavioral Workflow

Product status

Default status
unaffected

24.3-25.1
affected

Credits

Hussein Bahmad (NTT Data) finder

References

support.opentext.com/...henticated&sysparm_article=KB0839119

cve.org (CVE-2024-12543)

nvd.nist.gov (CVE-2024-12543)

Download JSON