← back
CVE-2025-2236

Exposure of Sensitive System Information vulnerability during configuration affecting OpenText Advanced Authentication.

CVSS 2.1 LOWEPSS 0.2%CWE-497
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.1EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 May 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue affects Advanced Authentication versions before 6.5.
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:P/AU:N/V:C/RE:M/U:Red

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →