CVE-2023-4550

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 29, 2024
Updated: Feb 5, 2024
CWE ID 89

Summary

CVE-2023-4550 is a files or directories accessible to external parties vulnerability affecting OpenText AppBuilder on both Windows and Linux platforms. This issue arises from improper input validation, allowing unauthenticated or authenticated users to probe system files. By exploiting a page within AppBuilder, an attacker can gain unauthorized access to read arbitrary files on the server. This vulnerability poses a significant risk, particularly for servers hosting sensitive data, as it affects AppBuilder versions from 21.2 up to but not including 23.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share