{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-5202","assignerOrgId":"f81092c5-7f14-476d-80dc-24857f90be84","state":"PUBLISHED","assignerShortName":"OpenText","dateReserved":"2024-05-22T15:03:55.602Z","datePublished":"2024-05-23T19:11:44.819Z","dateUpdated":"2024-08-01T21:03:11.078Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Dimensions RM","vendor":"OpenText","versions":[{"lessThan":"12.11.1.3","status":"affected","version":"0","versionType":"custom"},{"lessThan":"12.11.2.6","status":"affected","version":"12.11.2","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Telekom MMS GmbH (Researcher: P. Graf, M. Seidel, O. Vogel)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Arbitrary File Read&nbsp;in OpenText Dimensions RM allows&nbsp;authenticated users&nbsp;to read files stored on the server via webservices"}],"value":"Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices"}],"impacts":[{"capecId":"CAPEC-497","descriptions":[{"lang":"en","value":"CAPEC-497 File Discovery"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f81092c5-7f14-476d-80dc-24857f90be84","shortName":"OpenText","dateUpdated":"2024-05-23T19:11:44.819Z"},"references":[{"url":"https://portal.microfocus.com/s/article/KM000029988"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<a target=\"_blank\" rel=\"nofollow\" href=\"https://portal.microfocus.com/s/article/KM000029988\">https://portal.microfocus.com/s/article/KM000029988</a><br>"}],"value":"https://portal.microfocus.com/s/article/KM000029988"}],"source":{"discovery":"UNKNOWN"},"title":"Dimensions RM - Arbitrary File Read","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-5202","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-05-24T15:53:28.427133Z"}}}],"affected":[{"cpes":["cpe:2.3:a:opentext:dimensions_rm:*:*:*:*:*:*:*:*"],"vendor":"opentext","product":"dimensions_rm","versions":[{"status":"affected","version":"0","lessThan":"12.11.1.3","versionType":"custom"},{"status":"affected","version":"12.11.2","lessThan":"12.11.2.6","versionType":"custom"}],"defaultStatus":"unaffected"}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T18:01:45.588Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:03:11.078Z"},"title":"CVE Program Container","references":[{"url":"https://portal.microfocus.com/s/article/KM000029988","tags":["x_transferred"]}]}]}}