CVE-2023-4964

Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The vulnerability could allow attackers to redirect a user to malicious websites.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:asset_management_x:2021.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2021.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2022.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2022.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2020.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2020.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2020.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.02:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2022.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2022.11:*:*:*:*:*:*:*

History

08 Nov 2023, 00:16

Type Values Removed Values Added
First Time Microfocus service Management Automation X
Microfocus
Microfocus asset Management X
CPE cpe:2.3:a:microfocus:service_management_automation_x:2020.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2020.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2022.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2022.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2022.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2022.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2021.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:asset_management_x:2021.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2020.11:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.02:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_management_automation_x:2021.05:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-601
References (MISC) https://portal.microfocus.com/s/article/KM000022703?language=en_US - (MISC) https://portal.microfocus.com/s/article/KM000022703?language=en_US - Vendor Advisory

30 Oct 2023, 15:28

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-30 15:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-4964

Mitre link : CVE-2023-4964

CVE.ORG link : CVE-2023-4964


JSON object : View

Products Affected

microfocus

  • service_management_automation_x
  • asset_management_x
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')