OpenText's vulnerability footprint spans a modestly represented but strategically positioned portfolio of enterprise content management, document processing, and data analytics products that support document-heavy workflows across large organizations. The vendor's disclosures cluster around application-layer input handling and data-boundary issues, with recurring weaknesses including cross-site scripting, path traversal, input validation flaws, and out-of-bounds write conditions that reflect the complexity of parsing, transformation, and web-facing presentation in document-processing systems. Vulnerabilities affecting the vendor skew toward moderate severity outcomes, and a meaningful share acquire public exploit availability. The exposure concentrates in products such as Documentum Content Server, Brava! Desktop, Vertica, and extended ECM platforms, where document handling, access control, and integration depth create persistent risk surfaces. Defenders should prioritize patching document-processing endpoints and review file-handling configurations; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by OpenText (formerly Micro Focus) over time
Of all the CVEs published by OpenText (formerly Micro Focus) as a CNA, 6.3% affect products that OpenText (formerly Micro Focus) develops as a vendor.
Of all the CVEs published that affect products developed by OpenText (formerly Micro Focus), 30.2% are self-published by OpenText (formerly Micro Focus) as a CNA.
Signals from CVEs in this vendor scope (126 CVEs).
126 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5586CRITICAL OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) a | Feb 22, 2017 | 9.8 | 56 | NO | YES |
CVE-2017-15276HIGH OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser priv | Oct 13, 2017 | 8.8 | 44 | NO | YES |
CVE-2017-15012HIGH OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authentic | Oct 13, 2017 | 8.8 | 43 | NO | YES |
CVE-2017-15013HIGH OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser priv | Oct 13, 2017 | 8.8 | 42 | NO | YES |
CVE-2017-7221HIGH OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user p | Apr 25, 2017 | 8.8 | 41 | NO | YES |
CVE-2022-45926HIGH An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports. | Jan 18, 2023 | 8.8 | 37 | NO | NO |
CVE-2017-14758HIGH OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/ | Oct 3, 2017 | 8.8 | 36 | NO | YES |
CVE-2017-14757HIGH OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/h | Oct 3, 2017 | 8.8 | 36 | NO | YES |
CVE-2022-45925HIGH An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the respons | Jan 18, 2023 | 7.5 | 33 | NO | NO |
CVE-2017-14960HIGH xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. | Jan 4, 2018 | 7.5 | 33 | NO | YES |
Signals from CVEs in this vendor scope (126 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by OpenText (formerly Micro Focus).
Media articles that mention a CVE ID that affects a product developed by OpenText (formerly Micro Focus) — matched by CVE ID, not by vendor name.