CVE Feed

    Dashboard / CVE / CVE-2022-41221

    CVE-2022-41221

    The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

    Published:May 24, 2023
    Last Modified:Jan 17, 2025
    EPS:May 24, 2023
    EPSS Score:0.00024
    CVSS Score:7.1

    Affected Products

    Vendor
    Opentext
    Product
    Archive Center Administration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High