Opentext
opentext
124 CVEs • 36 products
Products (36)
Click to collapseToggle
Products (36)
Click to collapse
CVEs (124)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Opentext 1Document Sciences Xpression May 13, 2026 Oct 3, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource_group_xsd.jsp, param...Show more |
1Opentext 2Documentum Administrator Documentum WebtopMay 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of s...Show more |
1Opentext 2Documentum Administrator Documentum WebtopMay 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a deni...Show more |
1Opentext 2Documentum Administrator Documentum WebtopMay 13, 2026 Sep 28, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xd...Show more |
1Opentext 2Documentum Administrator Documentum WebtopMay 13, 2026 Sep 28, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat paramete...Show more |
Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image. |
1Opentext 1Documentum Content Server May 13, 2026 Apr 25, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability...Show more |
1Opentext 1Documentum Content Server May 13, 2026 Apr 21, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" at...Show more |
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libr...Show more |
1Opentext 1Documentum Content Server May 13, 2026 Feb 22, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allow...Show more |
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPo...Show more |
The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914. |
1Opentext 2Secure Mft 2013 Secure Mft 2014May 6, 2026 Aug 20, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboar...Show more |
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network. |
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive informat...Show more |
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authen...Show more |
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a...Show more |
1Opentext 1Opentext/ixos Ecm For Sap Netweaver Apr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unspecified vulnerability in OpenText/IXOS ECM for SAP NetWeaver allows remote attackers to execute arbitrary ABAP code via unknown vectors. |
Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder and resource permission...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse act...Show more |