Refine your search
2 vulnerabilities found for Dimensions RM by OpenText
CVE-2024-5201 (GCVE-0-2024-5201)
Vulnerability from cvelistv5
Published
2024-05-23 19:11
Modified
2024-08-01 21:03
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-287 - Improper Authentication
Summary
Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Request
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| OpenText | Dimensions RM |
Version: 12.11.1.1 < 12.11.1.3 Version: 12.11.2 < 12.11.2.6 |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:opentext:dimensions_rm:12.11.1.1:*:*:*:*:*:*:*"
],
"defaultStatus": "affected",
"product": "dimensions_rm",
"vendor": "opentext",
"versions": [
{
"status": "affected",
"version": "12.11.1.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:opentext:dimensions_rm:12.11.2:*:*:*:*:*:*:*"
],
"defaultStatus": "affected",
"product": "dimensions_rm",
"vendor": "opentext",
"versions": [
{
"status": "affected",
"version": "12.11.2"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-5201",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-24T14:07:20.265547Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T18:03:04.750Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:03:11.090Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://portal.microfocus.com/s/article/KM000029985"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Dimensions RM",
"vendor": "OpenText",
"versions": [
{
"lessThan": "12.11.1.3",
"status": "affected",
"version": "12.11.1.1",
"versionType": "custom"
},
{
"lessThan": "12.11.2.6",
"status": "affected",
"version": "12.11.2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Telekom MMS GmbH (Researcher: P. Graf, M. Seidel, O. Vogel)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Privilege Escalation\u0026nbsp;in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user\u0026nbsp;via HTTP Request"
}
],
"value": "Privilege Escalation\u00a0in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user\u00a0via HTTP Request"
}
],
"impacts": [
{
"capecId": "CAPEC-151",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-151 Identity Spoofing"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-23T19:11:48.936Z",
"orgId": "f81092c5-7f14-476d-80dc-24857f90be84",
"shortName": "OpenText"
},
"references": [
{
"url": "https://portal.microfocus.com/s/article/KM000029985"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://portal.microfocus.com/s/article/KM000029985\"\u003ehttps://portal.microfocus.com/s/article/KM000029985\u003c/a\u003e\u003cbr\u003e"
}
],
"value": "https://portal.microfocus.com/s/article/KM000029985"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Dimensions RM - Privilege Escalation",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f81092c5-7f14-476d-80dc-24857f90be84",
"assignerShortName": "OpenText",
"cveId": "CVE-2024-5201",
"datePublished": "2024-05-23T19:11:48.936Z",
"dateReserved": "2024-05-22T15:03:51.701Z",
"dateUpdated": "2024-08-01T21:03:11.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-5202 (GCVE-0-2024-5202)
Vulnerability from cvelistv5
Published
2024-05-23 19:11
Modified
2024-08-01 21:03
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Summary
Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| OpenText | Dimensions RM |
Version: 0 < 12.11.1.3 Version: 12.11.2 < 12.11.2.6 |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:opentext:dimensions_rm:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "dimensions_rm",
"vendor": "opentext",
"versions": [
{
"lessThan": "12.11.1.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "12.11.2.6",
"status": "affected",
"version": "12.11.2",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-5202",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-24T15:53:28.427133Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T18:01:45.588Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:03:11.078Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://portal.microfocus.com/s/article/KM000029988"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Dimensions RM",
"vendor": "OpenText",
"versions": [
{
"lessThan": "12.11.1.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "12.11.2.6",
"status": "affected",
"version": "12.11.2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Telekom MMS GmbH (Researcher: P. Graf, M. Seidel, O. Vogel)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Arbitrary File Read\u0026nbsp;in OpenText Dimensions RM allows\u0026nbsp;authenticated users\u0026nbsp;to read files stored on the server via webservices"
}
],
"value": "Arbitrary File Read\u00a0in OpenText Dimensions RM allows\u00a0authenticated users\u00a0to read files stored on the server via webservices"
}
],
"impacts": [
{
"capecId": "CAPEC-497",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-497 File Discovery"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-23T19:11:44.819Z",
"orgId": "f81092c5-7f14-476d-80dc-24857f90be84",
"shortName": "OpenText"
},
"references": [
{
"url": "https://portal.microfocus.com/s/article/KM000029988"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://portal.microfocus.com/s/article/KM000029988\"\u003ehttps://portal.microfocus.com/s/article/KM000029988\u003c/a\u003e\u003cbr\u003e"
}
],
"value": "https://portal.microfocus.com/s/article/KM000029988"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Dimensions RM - Arbitrary File Read",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f81092c5-7f14-476d-80dc-24857f90be84",
"assignerShortName": "OpenText",
"cveId": "CVE-2024-5202",
"datePublished": "2024-05-23T19:11:44.819Z",
"dateReserved": "2024-05-22T15:03:55.602Z",
"dateUpdated": "2024-08-01T21:03:11.078Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}