Home

Description

In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known.

PUBLISHED Reserved 2025-08-07 | Published 2025-09-11 | Updated 2025-09-11 | Assigner OpenText




MEDIUM: 5.8CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-754 Improper Check for Unusual or Exceptional Conditions

Product status

Default status
unaffected

20.4-25.3
affected

Credits

Armin Stock finder

References

support.opentext.com/...henticated&sysparm_article=KB0847046

cve.org (CVE-2025-8716)

nvd.nist.gov (CVE-2025-8716)

Download JSON