In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-12-19 20:15
Updated : 2025-10-09 19:15
NVD link : CVE-2024-12111
Mitre link : CVE-2024-12111
CVE.ORG link : CVE-2024-12111
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
