Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-45925


An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.


Published

2023-01-18T21:15:10.897

Last Modified

2025-04-04T18:15:43.210

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application opentext opentext_extended_ecm ≤ 22.3 Yes

References