Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerability could allow access to the system via script injection.This issue affects Directory Services: 23.4.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00047}

epss

{'score': 0.00062}


Thu, 10 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerability could allow access to the system via script injection.This issue affects Directory Services: 23.4.
Title Remote code execution vulnerability discovered in OpenText™ Directory Services CE 23.4
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:Y/R:A/V:D/RE:L/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published: 2025-07-10T10:02:58.567Z

Updated: 2025-07-10T14:14:17.034Z

Reserved: 2024-08-09T15:58:10.650Z

Link: CVE-2024-7650

cve-icon Vulnrichment

Updated: 2025-07-10T14:14:13.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-10T10:15:32.253

Modified: 2025-07-10T13:17:30.017

Link: CVE-2024-7650

cve-icon Redhat

No data.