CVE-2021-38132Server-Side Request Forgery in Edirectory

Severity
9.8CRITICALNVD
CNA5.3
EPSS
0.1%
top 68.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12

Description

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDmicrofocus/edirectory< 9.2.6.0000
CVEListV5opentext/edirectory9.1.29.2.5.0000

🔴Vulnerability Details

2
CVEList
Possible External service interaction Vulnerability2024-09-12
GHSA
GHSA-7v38-xc68-49j2: Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory2024-09-12
CVE-2021-38132 — Server-Side Request Forgery | cvebase