PT-2025-20290 · Opentext · Opentext Operations Bridge Manager

CVE-2025-3272

·

Published

2025-05-07

·

Updated

2025-05-20

CVSS v4.0

6.7

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:L/U:Green
Name of the Vulnerable Software and Affected Versions OpenText Operations Bridge Manager versions 24.2 through 24.4
Description The issue allows authenticated users to change their password without providing their old password.
Recommendations For versions 24.2 and 24.4, update to a version that includes a fix for this issue to prevent unauthorized password changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3272

Affected Products

Opentext Operations Bridge Manager