CVE-2022-45925
If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 16.94% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- opentext/opentext extended ecm
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/170615/OpenText-Extended-ECM-22.3-File-Deletion-LFI-Privilege-Escsalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2023/Jan/14Exploit, Mailing List, Third Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-post-authentication-vulnerabilities-including-rce-opentexttm-extended-ecm/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/170615/OpenText-Extended-ECM-22.3-File-Deletion-LFI-Privilege-Escsalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2023/Jan/14Exploit, Mailing List, Third Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-post-authentication-vulnerabilities-including-rce-opentexttm-extended-ecm/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.