Записи OpenText
137 опубликованных записей вендора opentext.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 2,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-787 Out-of-bounds Write17
- CWE-20 Improper Input Validation9
- CWE-287 Improper Authentication8
- CWE-611 Improper Restriction of XML External Entity Reference5
- CWE-125 Out-of-bounds Read5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
137 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2017-5586Proof of concept | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java opentext · documentum d2 · CWE-20 | Критическая9,8 | — | 25,3 % | 22 февр. 2017 г. |
40В плане | CVE-2022-45926Эксплойта нет | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-918 | Высокая8,8 | — | 17,0 % | 18 янв. 2023 г. |
40В плане | CVE-2016-2002Эксплойта нет | The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x bopentext · vertica · CWE-77 | Критическая9,8 | — | 3,1 % | 20 апр. 2016 г. |
40В плане | CVE-2017-5802Эксплойта нет | A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.opentext · vertica | Критическая9,8 | — | 2,3 % | 15 февр. 2018 г. |
39Наблюдать | CVE-2017-14759Эксплойта нет | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-611 | Критическая9,8 | — | 1,3 % | 2 окт. 2017 г. |
39Наблюдать | CVE-2024-1147Эксплойта нет | Weak Access Control - Arbitrary file downloadopentext · pvcs version manager · CWE-287 | Критическая9,8 | — | 0,7 % | 21 мар. 2024 г. |
39Наблюдать | CVE-2024-1148Эксплойта нет | Weak Access Control - Arbitrary file uploadopentext · pvcs version manager · CWE-287 | Критическая9,8 | — | 0,7 % | 21 мар. 2024 г. |
39Наблюдать | CVE-2022-35898Эксплойта нет | OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.opentext · bizmanager · CWE-287 | Критическая9,8 | — | 0,6 % | 1 мая 2023 г. |
39Наблюдать | CVE-2024-1811Эксплойта нет | OpenText ArcSight Platform Remote Vulnerabilityopentext · arcsight platform | Критическая9,8 | — | 0,6 % | 20 мар. 2024 г. |
39Наблюдать | CVE-2023-7248Эксплойта нет | OpenText Vertica Management console might be prone to bypass via crafted requestsopentext · vertica · CWE-20 | Критическая9,8 | — | 0,3 % | 15 мар. 2024 г. |
39Наблюдать | CVE-2023-38535Эксплойта нет | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.opentext · exceed turbox · CWE-321 | Критическая9,8 | — | 0,3 % | 13 мар. 2024 г. |
39Наблюдать | CVE-2024-6359Эксплойта нет | Privilege escalation vulnerabilityopentext · arcsight intelligence · CWE-269 | Критическая9,8 | — | 0,3 % | 6 авг. 2024 г. |
38Наблюдать | CVE-2017-15276Proof of concept | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an aopentext · documentum content server · CWE-22 | Высокая8,8 | — | 9,5 % | 13 окт. 2017 г. |
37Наблюдать | CVE-2017-15012Proof of concept | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILEopentext · documentum content server · CWE-20 | Высокая8,8 | — | 7,8 % | 13 окт. 2017 г. |
37Наблюдать | CVE-2017-15013Proof of concept | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an aopentext · documentum content server · CWE-269 | Высокая8,8 | — | 6,6 % | 13 окт. 2017 г. |
36Наблюдать | CVE-2017-7221Proof of concept | OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to opentext · documentum content server · CWE-89 | Высокая8,8 | — | 4,2 % | 25 апр. 2017 г. |
36Наблюдать | CVE-2017-14758Proof of concept | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-89 | Высокая8,8 | — | 2,7 % | 2 окт. 2017 г. |
36Наблюдать | CVE-2017-7220Эксплойта нет | OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATEopentext · documentum content server · CWE-20 | Высокая8,8 | — | 2,0 % | 20 апр. 2017 г. |
36Наблюдать | CVE-2017-5585Эксплойта нет | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_rowopentext · documentum content server · CWE-74 | Высокая8,8 | — | 2,0 % | 22 февр. 2017 г. |
36Наблюдать | CVE-2017-14757Proof of concept | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-89 | Высокая8,8 | — | 1,9 % | 2 окт. 2017 г. |
36Наблюдать | CVE-2022-45923Эксплойта нет | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-502 | Высокая8,8 | — | 1,9 % | 18 янв. 2023 г. |
36Наблюдать | CVE-2022-45927Эксплойта нет | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-639 | Высокая8,8 | — | 1,9 % | 18 янв. 2023 г. |
36Наблюдать | CVE-2022-45928Эксплойта нет | A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-94 | Высокая8,8 | — | 1,7 % | 18 янв. 2023 г. |
36Наблюдать | CVE-2019-17082Эксплойта нет | Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass.opentext™ · accurev · CWE-522 | Критическая9,0 | — | 0,5 % | 26 нояб. 2024 г. |
35Наблюдать | CVE-2022-45925Эксплойта нет | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-200 | Высокая7,5 | — | 16,9 % | 18 янв. 2023 г. |
- CVE-2017-558647В плане
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java
КритическаяCVSS 9,8Proof of conceptEPSS 25 %opentext · documentum d222 февр. 2017 г.
- CVE-2022-4592640В плане
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
ВысокаяCVSS 8,8Эксплойта нетEPSS 17 %opentext · opentext extended ecm18 янв. 2023 г.
- CVE-2016-200240В плане
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x b
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %opentext · vertica20 апр. 2016 г.
- CVE-2017-580240В плане
A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %opentext · vertica15 февр. 2018 г.
- CVE-2017-1475939Наблюдать
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opentext · document sciences xpression2 окт. 2017 г.
- CVE-2024-114739Наблюдать
Weak Access Control - Arbitrary file download
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opentext · pvcs version manager21 мар. 2024 г.
- CVE-2024-114839Наблюдать
Weak Access Control - Arbitrary file upload
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opentext · pvcs version manager21 мар. 2024 г.
- CVE-2022-3589839Наблюдать
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opentext · bizmanager1 мая 2023 г.
- CVE-2024-181139Наблюдать
OpenText ArcSight Platform Remote Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opentext · arcsight platform20 мар. 2024 г.
- CVE-2023-724839Наблюдать
OpenText Vertica Management console might be prone to bypass via crafted requests
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %opentext · vertica15 мар. 2024 г.
- CVE-2023-3853539Наблюдать
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %opentext · exceed turbox13 мар. 2024 г.
- CVE-2024-635939Наблюдать
Privilege escalation vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %opentext · arcsight intelligence6 авг. 2024 г.
- CVE-2017-1527638Наблюдать
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an a
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %opentext · documentum content server13 окт. 2017 г.
- CVE-2017-1501237Наблюдать
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %opentext · documentum content server13 окт. 2017 г.
- CVE-2017-1501337Наблюдать
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an a
ВысокаяCVSS 8,8Proof of conceptEPSS 7 %opentext · documentum content server13 окт. 2017 г.
- CVE-2017-722136Наблюдать
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %opentext · documentum content server25 апр. 2017 г.
- CVE-2017-1475836Наблюдать
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %opentext · document sciences xpression2 окт. 2017 г.
- CVE-2017-722036Наблюдать
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %opentext · documentum content server20 апр. 2017 г.
- CVE-2017-558536Наблюдать
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %opentext · documentum content server22 февр. 2017 г.
- CVE-2017-1475736Наблюдать
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %opentext · document sciences xpression2 окт. 2017 г.
- CVE-2022-4592336Наблюдать
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %opentext · opentext extended ecm18 янв. 2023 г.
- CVE-2022-4592736Наблюдать
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %opentext · opentext extended ecm18 янв. 2023 г.
- CVE-2022-4592836Наблюдать
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %opentext · opentext extended ecm18 янв. 2023 г.
- CVE-2019-1708236Наблюдать
Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass.
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %opentext™ · accurev26 нояб. 2024 г.
- CVE-2022-4592535Наблюдать
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %opentext · opentext extended ecm18 янв. 2023 г.