Skip to main content

Insufficiently Protected Credentials

CVE-2025-13478

Severity High
Score 8.4/10

Summary

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).

  • LOW
  • NETWORK
  • NONE
  • LOW

CWE-522 - Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

References

Advisory Timeline

  • Published