PatchSiren cyber security CVE debrief
CVE-2025-13478 OpenText CVE debrief
CVE-2025-13478 debrief based on the supplied source corpus. The vulnerability is a cache misconfiguration issue in OpenText Identity Manager on Windows and Linux, allowing remote authenticated users to obtain another user's session data via insecure application cache handling. This affects Identity Manager version 25.2(v4.10.1). Defenders should assess exposure and prioritize patch application to prevent potential session data exposure. The CVE record and NVD entry provide details on this vulnerability, but the corpus lacks specific information on exploitation, impact, and remediation beyond patch application. To address this, defenders should verify and apply patches for OpenText
- Vendor
- OpenText
- Product
- Identity Manager
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-27
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-03-27
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for OpenText Identity Manager deployments, particularly those using version 25.2(v4.10.1), should assess exposure and prioritize patch application to prevent potential session data exposure.
Why it matters
CVE-2025-13478 is a high-severity vulnerability in OpenText Identity Manager that allows remote authenticated users to obtain another user's session data. Defenders should prioritize patch application and configuration review to prevent potential session data exposure.
- Potential exposure of user session data
- Need for patch application to prevent vulnerability exploitation
- Importance of verifying Identity Manager configurations for secure cache handling
- Potential impact on user session security
Technical summary
A cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).
Defensive priority
Defenders should prioritize verifying and applying patches for OpenText Identity Manager versions 25.2(v4.10.1) to prevent potential session data exposure.
Recommended defensive actions
- Verify and apply patches for OpenText Identity Manager version 25.2(v4.10.1)
- Review and update Identity Manager configurations to ensure secure cache handling
- Monitor for potential session data exposure
Evidence notes
The CVE record and NVD entry provide details on a cache misconfiguration vulnerability in OpenText Identity Manager. However, the corpus lacks specific information on exploitation, impact, and remediation beyond patch application.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-13478 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-13478
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-13478 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13478
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.microfocus.com/doc/2159/25.2/cvesecurityfix
-
Source reference
Unverified legacy reference
URL: https://docs.microfocus.com/doc/2159/25.2/releasenotesidentitymanager4101patch01
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.