CVE-2024-5532 - CVE House
Back to Database
Status published Low CVE-2024-5532

A stored XSS vulnerability has been discovered on OpenText™ Operations Agent (OA).

Vulnerability Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5532

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Marco Ventura, Claudia Bartolini, Massimiliano Brolli - TIM Group

Affected Vendor

OpenText™

View all reports →

Affected Software

Operations Agent
Vulnerable Versions:
12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26

Timeline

Official Publish: October 28th, 2024
Last Modified: October 29th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)