CVE-2022-35898

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
01/05/2023
Last modified:
30/01/2025

Description

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opentext:bizmanager:*:*:*:*:*:*:*:* 16.6.0.1 (excluding)