Improper Enforcement of Behavioral Workflow
CVE-2024-12543
Summary
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.
- HIGH
- NETWORK
- NONE
- HIGH
CWE-841 - Improper Enforcement of Behavioral Workflow
The software supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.
References
Advisory Timeline
- Published