Elevation of privileges vulnerability
Published Mar 25, 2024
8.5
HIGHCVSS 3.1
EPSS 0.38%
Description
By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations.
Affected products
-
- Version 10.0StatusaffectedConstraints<<=23.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| OpenText | Secure Content Manager | unaffected |
|
No data.
-
- Version 10.0StatusaffectedConstraints<=23.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Opentext | Secure Content Manager | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Apply the following patch builds in your data center.
Secure Content Manager 23.4 Patch 1: PH_215013 - Content Manager 23.4 Patch 1 Build 111 https://kmviewer.saas.microfocus.com/#/1566945 Secure Content Manager 23.3 Patch 1: PH_215044 - Content Manager 23.3 Patch 1 Build 434 https://kmviewer.saas.microfocus.com/#/1567049 Secure Content Manager 10.1 Patch 5: PH_215040 - Content Manager 10.1 Patch 5 Release Build 1054 Secure Content Manager 10.0 Patch 6: PH_215038 - Content Manager 10.0 Patch 6 Build 1402
References (1)
Change history (0)
No recorded changes yet.