Code Injection Vulnerability in OpenText Directory Services
CVE-2024-7650

6.3MEDIUM

Key Information:

Vendor
CVE Published:
10 July 2025

What is CVE-2024-7650?

An improper control of the generation of code vulnerability has been identified in OpenText™ Directory Services, specifically version 23.4. This flaw allows for potential remote code inclusion through script injection techniques. Attackers may exploit this vulnerability to execute unauthorized scripts within the affected system, leading to possible data breaches or further compromise of system integrity. Ensuring security measures are in place is crucial for mitigating the risks associated with this vulnerability.

Affected Version(s)

Directory Services 23.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.