Java Database Connectivity (JDBC) URL Manipulation
CVE-2023-4552

7.1HIGH

Key Information:

Vendor
OpenText
Vendor
CVE Published:
29 January 2024

Summary

An improper input validation vulnerability exists in OpenText AppBuilder, which operates on Windows and Linux platforms. This vulnerability allows an authenticated user, who possesses rights to create or manage existing databases, to exploit the AppBuilder server's security. Specifically, it enables unauthorized access to the server's local file system, potentially leading to data exposure or manipulation. Organizations utilizing AppBuilder versions prior to 23.2 should assess their security measures and explore remediation strategies to protect sensitive information.

Affected Version(s)

AppBuilder Windows 21.2 < 23.2

AppBuilder Windows 23.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Mathias
.