Lucene search

K
cveMitreCVE-2022-45925
HistoryJan 18, 2023 - 9:15 p.m.

CVE-2022-45925

2023-01-1821:15:10
mitre
web.nvd.nist.gov
42
cve-2022-45925
opentext content suite platform
information disclosure
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

73.0%

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.

Affected configurations

Nvd
Node
opentextopentext_extended_ecmRange16.2.222.3
VendorProductVersionCPE
opentextopentext_extended_ecm*cpe:2.3:a:opentext:opentext_extended_ecm:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

73.0%

Related for CVE-2022-45925