CVE-2023-7248
Estado: ModificadaCrítica (9.8)—
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.
The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the following Vertica Management Console versions: 10.x 11.1.1-24 or lower 12.0.4-18 or lower
Please upgrade to one of the following Vertica Management Console versions: 10.x to upgrade to latest versions from below. 11.1.1-25 12.0.4-19 23.x 24.x
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 22
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-7248",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-7248",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-03-18T14:06:10.703241Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@opentext.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.7,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@opentext.com",
"affectedData": [
{
"vendor": "Opentext",
"product": "Vertica Management Console",
"versions": [
{
"status": "affected",
"version": "10.x"
},
{
"status": "affected",
"version": "11.x",
"versionType": "custom",
"lessThanOrEqual": "11.1.1-24"
},
{
"status": "affected",
"version": "12.x",
"versionType": "custom",
"lessThanOrEqual": "12.0.4-18"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:opentext:vertica_management_console:10.0:*:*:*:*:*:*:*"
],
"vendor": "opentext",
"product": "vertica_management_console",
"versions": [
{
"status": "affected",
"version": "10.0",
"lessThan": "11.0",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:opentext:vertica_management_console:11.0:*:*:*:*:*:*:*"
],
"vendor": "opentext",
"product": "vertica_management_console",
"versions": [
{
"status": "affected",
"version": "11.0",
"versionType": "custom",
"lessThanOrEqual": "11.1.1-24"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:opentext:vertica_management_console:12.0:*:*:*:*:*:*:*"
],
"vendor": "opentext",
"product": "vertica_management_console",
"versions": [
{
"status": "affected",
"version": "12.0",
"versionType": "custom",
"lessThanOrEqual": "12.0.4-18"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-15T20:15:07.280",
"references": [
{
"url": "https://portal.microfocus.com/s/article/KM000027542?language=en_US",
"tags": [
"Vendor Advisory"
],
"source": "security@opentext.com"
},
{
"url": "https://portal.microfocus.com/s/article/KM000027542?language=en_US",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@opentext.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\nCertain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. \n\nThe vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. \nThis issue impacts the following Vertica Management Console versions:\n10.x\n11.1.1-24 or lower\n12.0.4-18 or lower\n\nPlease upgrade to one of the following Vertica Management Console versions:\n10.x to upgrade to latest versions from below.\n11.1.1-25\n12.0.4-19\n23.x\n24.x\n\n"
},
{
"lang": "es",
"value": "Ciertas funciones en la consola de OpenText Vertica Management pueden ser propensas a omitirse mediante solicitudes manipuladas. La vulnerabilidad afectaría una de las funcionalidades de autenticación de Vertica al permitir solicitudes y secuencias especialmente manipuladas. Este problema afecta las siguientes versiones de Vertica Management Console: 10.x 11.1.1-24 o anterior 12.0.4-18 o anterior Actualice a una de las siguientes versiones de Vertica Management Console: 10.x para actualizar a las últimas versiones desde abajo. 11.1.1-25 12.0.4-19 23.x 24.x"
}
],
"lastModified": "2026-06-17T06:52:24.393",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "056D6A40-95C6-4FEA-91C9-B5C41AE254C4",
"versionEndIncluding": "10.1.1-26",
"versionStartIncluding": "10.0.0-0"
},
{
"criteria": "cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C15386AE-A142-4A50-9B64-276C2FC3E959",
"versionEndExcluding": "11.1.1-25",
"versionStartIncluding": "11.0.0-0"
},
{
"criteria": "cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84FC2248-AAC2-4994-BBB3-6705EAB9934B",
"versionEndExcluding": "12.0.4-19",
"versionStartIncluding": "12.0.0-0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@opentext.com"
}