CVE-2023-7249

Executive Summary

OpenText Directory Services versions 16.4.2 through 24.0 are vulnerable to a path traversal flaw (CVE‑2023‑7249) that allows attackers to read or write arbitrary files outside the intended directory. The flaw arises from improper pathname validation, enabling remote exploitation without authentication. Affected installations should apply the vendor‑issued patch or upgrade to 24.1 or later. The vulnerability is not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2024-08-12T16:15:14.173 - Last Modified: 2026-09-03T02:15:17.453

Original Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

"Great indeed is the sublimity of the Creative, to which all beings owe their beginning and which permeates all heaven."

— Lao Tzu
Source: NVD