Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

OpenText (formerly Micro Focus)

First CVE: Aug 22, 2001Active for: 25 yearsTotal CVEs: 126
45.9
VTI Score
High

OpenText's vulnerability footprint spans a modestly represented but strategically positioned portfolio of enterprise content management, document processing, and data analytics products that support document-heavy workflows across large organizations. The vendor's disclosures cluster around application-layer input handling and data-boundary issues, with recurring weaknesses including cross-site scripting, path traversal, input validation flaws, and out-of-bounds write conditions that reflect the complexity of parsing, transformation, and web-facing presentation in document-processing systems. Vulnerabilities affecting the vendor skew toward moderate severity outcomes, and a meaningful share acquire public exploit availability. The exposure concentrates in products such as Documentum Content Server, Brava! Desktop, Vertica, and extended ECM platforms, where document handling, access control, and integration depth create persistent risk surfaces. Defenders should prioritize patching document-processing endpoints and review file-handling configurations; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
126
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by OpenText (formerly Micro Focus) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2001
24 years ago
Most Recent CVE
Mar 18, 2026
128 days ago

Self-Reporting Analysis

Of all the CVEs published by OpenText (formerly Micro Focus) as a CNA, 6.3% affect products that OpenText (formerly Micro Focus) develops as a vendor.

93.7%
Self-reported: 38 (6.3%)
Third-party: 568 (93.7%)

Of all the CVEs published that affect products developed by OpenText (formerly Micro Focus), 30.2% are self-published by OpenText (formerly Micro Focus) as a CNA.

30.2%
69.8%
Self-published: 38 (30.2%)
Other CNAs: 88 (69.8%)

Products(36 total)

Top CVEs

Signals from CVEs in this vendor scope (126 CVEs).

126 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5586CRITICAL
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) a
Feb 22, 20179.856NOYES
CVE-2017-15276HIGH
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser priv
Oct 13, 20178.844NOYES
CVE-2017-15012HIGH
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authentic
Oct 13, 20178.843NOYES
CVE-2017-15013HIGH
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser priv
Oct 13, 20178.842NOYES
CVE-2017-7221HIGH
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user p
Apr 25, 20178.841NOYES
CVE-2022-45926HIGH
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.
Jan 18, 20238.837NONO
CVE-2017-14758HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/
Oct 3, 20178.836NOYES
CVE-2017-14757HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/h
Oct 3, 20178.836NOYES
CVE-2022-45925HIGH
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the respons
Jan 18, 20237.533NONO
CVE-2017-14960HIGH
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.
Jan 4, 20187.533NOYES
View all 126 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products126 CVEs
33%
56%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local39 (31.0%)
Network73 (57.9%)
Unknown14 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low111 (88.1%)
High1 (0.8%)
Unknown14 (11.1%)
User Interaction
None55 (43.7%)
Unknown14 (11.1%)
Required57 (45.2%)
Privileges Required
Low37 (29.4%)
High1 (0.8%)
None74 (58.7%)
Unknown14 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (126 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.8% of CVEs· 95th percentile
ExploitDB
10 CVEs
7.9% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by OpenText (formerly Micro Focus).

Media Mentions

Media articles that mention a CVE ID that affects a product developed by OpenText (formerly Micro Focus) — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For OpenText (formerly Micro Focus)'s Products

View all 4 CNAs →

Top CWEs