CVE-2024-12862 MEDIUM

CVE-2024-12862: REST API allows users without permissions to remove external collaborators

Vendor Opentext
Product Content Server
Weakness CWE-863 · Incorrect authorization
Published April 21, 2025
Last update April 21, 2025

CVSS base score

5.5/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4.

Key dates

02Disclosure timeline

April 21, 2025 CVE published
April 21, 2025 Record updated