Server-Side Request Forgery Vulnerability in OpenText XM Fax Product
CVE-2025-8055

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 February 2026

What is CVE-2025-8055?

A Server-Side Request Forgery (SSRF) vulnerability exists in OpenText™ XM Fax, enabling attackers to send crafted requests that can impersonate client-side requests to internal systems. This could expose sensitive information and lead to unauthorized access to network resources from the XM Fax server. Organizations using XM Fax version 24.2 should assess their security posture and take necessary precautions to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

XM Fax 24.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Inetum Hacking team, leaded in this research by Ángel M Sequeira and with the help of @cr33pb0y
.