Vulnerability Description
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opentext | Bizmanager | < 16.6.0.1 |
Related Weaknesses (CWE)
References
- https://businessnetwork.opentext.com/b2b-gateway/Product
- https://hackandpwn.com/disclosures/CVE-2022-35898.pdfThird Party Advisory
- https://businessnetwork.opentext.com/b2b-gateway/Product
- https://hackandpwn.com/disclosures/CVE-2022-35898.pdfThird Party Advisory
FAQ
What is CVE-2022-35898?
CVE-2022-35898 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the ...
How severe is CVE-2022-35898?
CVE-2022-35898 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-35898?
Check the references section above for vendor advisories and patch information. Affected products include: Opentext Bizmanager.