OpenText records
137 published records for vendor opentext.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 2.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-787 Out-of-bounds Write17
- CWE-20 Improper Input Validation9
- CWE-287 Improper Authentication8
- CWE-611 Improper Restriction of XML External Entity Reference5
- CWE-125 Out-of-bounds Read5
The weakness classes this vendor ships most often: where to look.
CWEAll records
137 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2017-5586Proof of concept | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java opentext · documentum d2 · CWE-20 | Critical9.8 | — | 25.3% | Feb 22, 2017 |
40Plan | CVE-2022-45926No exploit | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-918 | High8.8 | — | 17.0% | Jan 18, 2023 |
40Plan | CVE-2016-2002No exploit | The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x bopentext · vertica · CWE-77 | Critical9.8 | — | 3.1% | Apr 20, 2016 |
40Plan | CVE-2017-5802No exploit | A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.opentext · vertica | Critical9.8 | — | 2.3% | Feb 15, 2018 |
39Monitor | CVE-2017-14759No exploit | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-611 | Critical9.8 | — | 1.3% | Oct 2, 2017 |
39Monitor | CVE-2024-1147No exploit | Weak Access Control - Arbitrary file downloadopentext · pvcs version manager · CWE-287 | Critical9.8 | — | 0.7% | Mar 21, 2024 |
39Monitor | CVE-2024-1148No exploit | Weak Access Control - Arbitrary file uploadopentext · pvcs version manager · CWE-287 | Critical9.8 | — | 0.7% | Mar 21, 2024 |
39Monitor | CVE-2022-35898No exploit | OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.opentext · bizmanager · CWE-287 | Critical9.8 | — | 0.6% | May 1, 2023 |
39Monitor | CVE-2024-1811No exploit | OpenText ArcSight Platform Remote Vulnerabilityopentext · arcsight platform | Critical9.8 | — | 0.6% | Mar 20, 2024 |
39Monitor | CVE-2023-7248No exploit | OpenText Vertica Management console might be prone to bypass via crafted requestsopentext · vertica · CWE-20 | Critical9.8 | — | 0.3% | Mar 15, 2024 |
39Monitor | CVE-2023-38535No exploit | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.opentext · exceed turbox · CWE-321 | Critical9.8 | — | 0.3% | Mar 13, 2024 |
39Monitor | CVE-2024-6359No exploit | Privilege escalation vulnerabilityopentext · arcsight intelligence · CWE-269 | Critical9.8 | — | 0.3% | Aug 6, 2024 |
38Monitor | CVE-2017-15276Proof of concept | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an aopentext · documentum content server · CWE-22 | High8.8 | — | 9.5% | Oct 13, 2017 |
37Monitor | CVE-2017-15012Proof of concept | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILEopentext · documentum content server · CWE-20 | High8.8 | — | 7.8% | Oct 13, 2017 |
37Monitor | CVE-2017-15013Proof of concept | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an aopentext · documentum content server · CWE-269 | High8.8 | — | 6.6% | Oct 13, 2017 |
36Monitor | CVE-2017-7221Proof of concept | OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to opentext · documentum content server · CWE-89 | High8.8 | — | 4.2% | Apr 25, 2017 |
36Monitor | CVE-2017-14758Proof of concept | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-89 | High8.8 | — | 2.7% | Oct 2, 2017 |
36Monitor | CVE-2017-7220No exploit | OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATEopentext · documentum content server · CWE-20 | High8.8 | — | 2.0% | Apr 20, 2017 |
36Monitor | CVE-2017-5585No exploit | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_rowopentext · documentum content server · CWE-74 | High8.8 | — | 2.0% | Feb 22, 2017 |
36Monitor | CVE-2017-14757Proof of concept | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-89 | High8.8 | — | 1.9% | Oct 2, 2017 |
36Monitor | CVE-2022-45923No exploit | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-502 | High8.8 | — | 1.9% | Jan 18, 2023 |
36Monitor | CVE-2022-45927No exploit | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-639 | High8.8 | — | 1.9% | Jan 18, 2023 |
36Monitor | CVE-2022-45928No exploit | A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-94 | High8.8 | — | 1.7% | Jan 18, 2023 |
36Monitor | CVE-2019-17082No exploit | Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass.opentext™ · accurev · CWE-522 | Critical9.0 | — | 0.5% | Nov 26, 2024 |
35Monitor | CVE-2022-45925No exploit | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-200 | High7.5 | — | 16.9% | Jan 18, 2023 |
- CVE-2017-558647Plan
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java
CriticalCVSS 9.8Proof of conceptEPSS 25%opentext · documentum d2Feb 22, 2017
- CVE-2022-4592640Plan
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
HighCVSS 8.8No exploitEPSS 17%opentext · opentext extended ecmJan 18, 2023
- CVE-2016-200240Plan
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x b
CriticalCVSS 9.8No exploitEPSS 3%opentext · verticaApr 20, 2016
- CVE-2017-580240Plan
A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.
CriticalCVSS 9.8No exploitEPSS 2%opentext · verticaFeb 15, 2018
- CVE-2017-1475939Monitor
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
CriticalCVSS 9.8No exploitEPSS 1%opentext · document sciences xpressionOct 2, 2017
- CVE-2024-114739Monitor
Weak Access Control - Arbitrary file download
CriticalCVSS 9.8No exploitEPSS 1%opentext · pvcs version managerMar 21, 2024
- CVE-2024-114839Monitor
Weak Access Control - Arbitrary file upload
CriticalCVSS 9.8No exploitEPSS 1%opentext · pvcs version managerMar 21, 2024
- CVE-2022-3589839Monitor
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.
CriticalCVSS 9.8No exploitEPSS 1%opentext · bizmanagerMay 1, 2023
- CVE-2024-181139Monitor
OpenText ArcSight Platform Remote Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%opentext · arcsight platformMar 20, 2024
- CVE-2023-724839Monitor
OpenText Vertica Management console might be prone to bypass via crafted requests
CriticalCVSS 9.8No exploitEPSS 0%opentext · verticaMar 15, 2024
- CVE-2023-3853539Monitor
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.
CriticalCVSS 9.8No exploitEPSS 0%opentext · exceed turboxMar 13, 2024
- CVE-2024-635939Monitor
Privilege escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 0%opentext · arcsight intelligenceAug 6, 2024
- CVE-2017-1527638Monitor
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an a
HighCVSS 8.8Proof of conceptEPSS 9%opentext · documentum content serverOct 13, 2017
- CVE-2017-1501237Monitor
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE
HighCVSS 8.8Proof of conceptEPSS 8%opentext · documentum content serverOct 13, 2017
- CVE-2017-1501337Monitor
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an a
HighCVSS 8.8Proof of conceptEPSS 7%opentext · documentum content serverOct 13, 2017
- CVE-2017-722136Monitor
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to
HighCVSS 8.8Proof of conceptEPSS 4%opentext · documentum content serverApr 25, 2017
- CVE-2017-1475836Monitor
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
HighCVSS 8.8Proof of conceptEPSS 3%opentext · document sciences xpressionOct 2, 2017
- CVE-2017-722036Monitor
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE
HighCVSS 8.8No exploitEPSS 2%opentext · documentum content serverApr 20, 2017
- CVE-2017-558536Monitor
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row
HighCVSS 8.8No exploitEPSS 2%opentext · documentum content serverFeb 22, 2017
- CVE-2017-1475736Monitor
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
HighCVSS 8.8Proof of conceptEPSS 2%opentext · document sciences xpressionOct 2, 2017
- CVE-2022-4592336Monitor
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
HighCVSS 8.8No exploitEPSS 2%opentext · opentext extended ecmJan 18, 2023
- CVE-2022-4592736Monitor
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
HighCVSS 8.8No exploitEPSS 2%opentext · opentext extended ecmJan 18, 2023
- CVE-2022-4592836Monitor
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
HighCVSS 8.8No exploitEPSS 2%opentext · opentext extended ecmJan 18, 2023
- CVE-2019-1708236Monitor
Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass.
CriticalCVSS 9.0No exploitEPSS 0%opentext™ · accurevNov 26, 2024
- CVE-2022-4592535Monitor
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
HighCVSS 7.5No exploitEPSS 17%opentext · opentext extended ecmJan 18, 2023