Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35898


OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.


Published

2023-05-01T20:15:14.463

Last Modified

2025-01-30T17:15:11.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-287
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application opentext bizmanager < 16.6.0.1 Yes

References