Incorrect Authorization in OpenText Operations Bridge Manager
CVE-2025-3272
6.7MEDIUM
What is CVE-2025-3272?
An incorrect authorization vulnerability exists in OpenText's Operations Bridge Manager, allowing authenticated users to reset their passwords without inputting their old passwords. This flaw could potentially be exploited to gain unauthorized access and control over user accounts, posing a significant security risk for organizations relying on this management tool. It is crucial for users of Operations Bridge Manager 24.2 and 24.4 to apply the latest patches to mitigate this vulnerability.
Affected Version(s)
Operations Bridge Manager 24.2
Operations Bridge Manager 24.4
References
CVSS V4
Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved