An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted.
This issue affects AppBuilder: from 21.2 before 23.2.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54405 | Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted. This issue affects AppBuilder: from 21.2 before 23.2. |
Tue, 12 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: OpenText
Published:
Updated: 2024-11-12T21:30:04.904Z
Reserved: 2023-08-25T16:54:44.535Z
Link: CVE-2023-4550
Updated: 2024-08-02T07:31:06.538Z
Status : Modified
Published: 2024-01-29T21:15:08.670
Modified: 2024-11-21T08:35:24.040
Link: CVE-2023-4550
No data.
OpenCVE Enrichment
No data.
EUVD