OpenText BizManager before 16.6.0.1 does not perform...
Critical severity
Unreviewed
Published
May 1, 2023
to the GitHub Advisory Database
•
Updated Jan 30, 2025
Description
Published by the National Vulnerability Database
May 1, 2023
Published to the GitHub Advisory Database
May 1, 2023
Last updated
Jan 30, 2025
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
References