Incorrect Authorization in OpenText Operations Bridge Manager
CVE-2025-3272

6.7MEDIUM

Key Information:

Vendor
CVE Published:
7 May 2025

What is CVE-2025-3272?

An incorrect authorization vulnerability exists in OpenText's Operations Bridge Manager, allowing authenticated users to reset their passwords without inputting their old passwords. This flaw could potentially be exploited to gain unauthorized access and control over user accounts, posing a significant security risk for organizations relying on this management tool. It is crucial for users of Operations Bridge Manager 24.2 and 24.4 to apply the latest patches to mitigate this vulnerability.

Affected Version(s)

Operations Bridge Manager 24.2

Operations Bridge Manager 24.4

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3272 : Incorrect Authorization in OpenText Operations Bridge Manager