// For flags

CVE-2023-4964

Potential open redirect vulnerability in opentext SMAX and AMX product.

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Potential open redirect vulnerability
in opentext Service Management Automation X
(SMAX) versions 2020.05, 2020.08,
2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset
Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The
vulnerability could allow attackers to redirect a user to
malicious websites.

Posible vulnerabilidad de redireccionamiento abierto en opentext Service Management Automation X (SMAX) versiones 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 y opentext Asset Management X (AMX) versiones 2021.08, 2 021.11, 2022.05, 2022.11. La vulnerabilidad podrĂ­a permitir a los atacantes redirigir a un usuario a sitios web maliciosos.

*Credits: Abel Iglesias Iglesias (a.k.a. Hurd4n0)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-09-14 CVE Reserved
  • 2023-10-30 CVE Published
  • 2024-09-06 CVE Updated
  • 2024-11-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microfocus
Search vendor "Microfocus"
Asset Management X
Search vendor "Microfocus" for product "Asset Management X"
2021.08
Search vendor "Microfocus" for product "Asset Management X" and version "2021.08"
-
Affected
Microfocus
Search vendor "Microfocus"
Asset Management X
Search vendor "Microfocus" for product "Asset Management X"
2021.11
Search vendor "Microfocus" for product "Asset Management X" and version "2021.11"
-
Affected
Microfocus
Search vendor "Microfocus"
Asset Management X
Search vendor "Microfocus" for product "Asset Management X"
2022.05
Search vendor "Microfocus" for product "Asset Management X" and version "2022.05"
-
Affected
Microfocus
Search vendor "Microfocus"
Asset Management X
Search vendor "Microfocus" for product "Asset Management X"
2022.11
Search vendor "Microfocus" for product "Asset Management X" and version "2022.11"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2020.05
Search vendor "Microfocus" for product "Service Management Automation X" and version "2020.05"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2020.08
Search vendor "Microfocus" for product "Service Management Automation X" and version "2020.08"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2020.11
Search vendor "Microfocus" for product "Service Management Automation X" and version "2020.11"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2021.02
Search vendor "Microfocus" for product "Service Management Automation X" and version "2021.02"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2021.05
Search vendor "Microfocus" for product "Service Management Automation X" and version "2021.05"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2021.08
Search vendor "Microfocus" for product "Service Management Automation X" and version "2021.08"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2021.11
Search vendor "Microfocus" for product "Service Management Automation X" and version "2021.11"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2022.05
Search vendor "Microfocus" for product "Service Management Automation X" and version "2022.05"
-
Affected
Microfocus
Search vendor "Microfocus"
Service Management Automation X
Search vendor "Microfocus" for product "Service Management Automation X"
2022.11
Search vendor "Microfocus" for product "Service Management Automation X" and version "2022.11"
-
Affected