OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpentext Bizmanager
APPOpentext< 16.6.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2017-5802CRITICAL9.8PL ✓same vendor
Zdalne przejęcie uprawnień w HPE Vertica Analytics Platform
CVE-2017-14759CRITICAL9.8PL ✓same vendor
XXE w OpenText xPression — nieautoryzowany odczyt plików i SSRF
CVE-2017-5586CRITICAL9.8PL ✓same vendor
RCE w OpenText Documentum D2 4.x przez deserializację Java
CVE-2016-2002CRITICAL9.8PL ✓same vendor
Command injection w HPE Vertica Analytics Management Console (mcPort)
CVE-2026-3278HIGH7.4same vendor
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText...