Home
MEDIUM: 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
20.4-25.3
affected
Description
In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known.
Problem types
CWE-754 Improper Check for Unusual or Exceptional Conditions
Product status
20.4-25.3
Credits
Armin Stock
References
support.opentext.com/...henticated&sysparm_article=KB0847046