Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack.

Project Subscriptions

Vendors Products
Opentext Subscribe
Alm Octane Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47469 Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack.
Fixes

Solution

https://portal.microfocus.com/s/article/KM000032605


Workaround

No workaround given by the vendor.

History

Wed, 28 Aug 2024 18:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 06 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Opentext
Opentext alm Octane
CPEs cpe:2.3:a:opentext:alm_octane:*:*:*:*:*:*:*:*
Vendors & Products Opentext
Opentext alm Octane
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2024-11-01T17:44:47.667Z

Reserved: 2024-06-26T20:35:12.099Z

Link: CVE-2024-6361

cve-icon Vulnrichment

Updated: 2024-08-06T20:02:48.820Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-05T19:15:38.333

Modified: 2024-08-28T18:17:35.497

Link: CVE-2024-6361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses