Skip to main content

Improper Enforcement of Behavioral Workflow

CVE-2024-12543

Severity Medium
Score 5.9/10

Summary

User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.

  • HIGH
  • NETWORK
  • NONE
  • HIGH

CWE-841 - Improper Enforcement of Behavioral Workflow

The software supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

References

Advisory Timeline

  • Published