Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenText — Vulnerabilities & Security Advisories 148

Browse all 148 CVE security advisories affecting OpenText. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenText operates as a global enterprise information management provider, offering solutions for content management, digital asset management, and analytics. Its extensive software portfolio, including Content Server and Exstream, has historically been a frequent target for security researchers, resulting in a significant number of recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes affecting these platforms include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation or improper access controls. While the company maintains standard security protocols, the sheer volume of its legacy and integrated applications creates a broad attack surface. Recent incidents highlight the critical need for rigorous patch management and continuous monitoring to mitigate risks associated with these complex enterprise systems, ensuring that sensitive data remains protected against evolving cyber threats.

CVE ID Title CVSS Severity Published
CVE-2024-4555 User impersonation with MFA when configure in specific way — NetIQ Access Manager CWE-266 7.7 High 2024-08-28
CVE-2024-4556 Directory traversal vulnerability in NetIQ Access Manager — NetIQ Access Manager CWE-22 5.7 Medium 2024-08-28
CVE-2022-26327 Stored cross-site scripting (XSS) has been discovered in OpenText™ Performance Center — Performance Center CWE-200 7.5 - 2024-08-21
CVE-2022-26328 User enumeration vulnerability has been discovered in OpenText™ Performance Center — Performance Center CWE-79 6.1AI Medium AI 2024-08-21
CVE-2020-11847 Vulnerability in sshrelay in privileged access manager provides full system access. — Privileged Access Manager CWE-78 8.2 High 2024-08-21
CVE-2020-11846 Improper handling of token allows access to restricted resource in Privileged Access Manager — Privileged Access Manager CWE-269 8.7 High 2024-08-21
CVE-2020-11850 Cross site scripting vulnerability in Self Service Password Reset — Self Service Password Reset CWE-20 7.3 High 2024-08-21
CVE-2023-7249 OpenText Directory Services 安全漏洞 — OpenText Directory Services CWE-22 6.5AI Medium AI 2024-08-12
CVE-2024-6357 Insecure Direct Object Reference vulnerability — ArcSight Intelligence CWE-639 6.3 Medium 2024-08-06
CVE-2024-6359 Privilege escalation vulnerability — ArcSight Intelligence CWE-269 6.4 Medium 2024-08-06
CVE-2024-6358 Incorrect Authorization vulnerability — ArcSight Intelligence CWE-863 6.3 Medium 2024-08-06
CVE-2024-7050 OpenText Directory Services 安全漏洞 — OpenText Directory Services CWE-287 9.1 - 2024-07-26
CVE-2020-25836 Potential information leakage resulting in unauthorized access — NetIQ Directory and Resource Administrator CWE-200 6.3 Medium 2024-07-16
CVE-2024-4190 OpenText ArcSight Logger Stored XSS — ArcSight Logger CWE-79 8.1 High 2024-06-11
CVE-2020-11843 Potential information leakage in administrator enabled debug mode — NetIQ Access Manager CWE-200 6.5 Medium 2024-06-11
CVE-2024-4429 Cross Site Request Forgery vulnerability in iManager — iManager CWE-352 5.4 Medium 2024-05-28
CVE-2024-3969 XML External Entity injection vulnerability in iManager — iManager CWE-611 7.8 High 2024-05-28
CVE-2024-5201 Dimensions RM - Privilege Escalation — Dimensions RM CWE-287 8.8 High 2024-05-23
CVE-2024-5202 Dimensions RM - Arbitrary File Read — Dimensions RM CWE-200 7.7 High 2024-05-23
CVE-2024-2835 OpenText ArcSight Enterprise Security Manager and ArcSight Platform Stored XSS — ArcSight Enterprise Security Manager CWE-79 8.7 High 2024-05-20
CVE-2024-3482 OpenText ArcSight Enterprise Security Manager and ArcSight Platform Stored XSS — ArcSight Enterprise Security Manager CWE-79 8.7 High 2024-05-20
CVE-2021-22508 Potential SQL injection in OpenText Operations Bridge Reporter — Operations Bridge Reporter CWE-20 7.2 High 2024-05-17
CVE-2024-3488 File Upload vulnerability in unauthenticated session found in iManager. — iManager CWE-20 5.6 Medium 2024-05-15
CVE-2024-3487 Broken Authentication vulnerability in iManager — iManager CWE-287 3.5 Low 2024-05-15
CVE-2024-3486 XML External Entity injection vulnerability in iManager — iManager CWE-611 7.8 High 2024-05-15
CVE-2024-3485 Server-Side Request Forgery vulnerability in iManager — iManager CWE-918 5.3 Medium 2024-05-15
CVE-2024-3484 Path Traversal vulnerability found in iManager — iManager CWE-22 5.7 Medium 2024-05-15
CVE-2024-3483 Remote Code Execution vulnerability in the iManager — iManager CWE-502 7.8 High 2024-05-15
CVE-2024-3967 Remote Code Execution vulnerability in the iManager — iManager CWE-502 7.6 High 2024-05-15
CVE-2024-3968 Remote Code Execution vulnerability in the iManager — iManager CWE-20 7.8 High 2024-05-15

This page lists every published CVE security advisory associated with OpenText. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.