CVE-2024-4188

July 30, 2024, 3:15 p.m.

Product(s) Impacted

OpenText Documentum Server

  • 16.7 through 23.4

Description

Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

Weaknesses

CWE-523
Unprotected Transport of Credentials

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

CWE ID: 523

Date

Published: July 30, 2024, 3:15 p.m.

Last Modified: July 30, 2024, 3:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@opentext.com

References