PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13478 OpenText CVE debrief

CVE-2025-13478 debrief based on the supplied source corpus. The vulnerability is a cache misconfiguration issue in OpenText Identity Manager on Windows and Linux, allowing remote authenticated users to obtain another user's session data via insecure application cache handling. This affects Identity Manager version 25.2(v4.10.1). Defenders should assess exposure and prioritize patch application to prevent potential session data exposure. The CVE record and NVD entry provide details on this vulnerability, but the corpus lacks specific information on exploitation, impact, and remediation beyond patch application. To address this, defenders should verify and apply patches for OpenText

Vendor
OpenText
Product
Identity Manager
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-27
Original CVE updated
2026-09-30
Advisory published
2026-03-27
Advisory updated
2026-09-30

Who should care

Defenders responsible for OpenText Identity Manager deployments, particularly those using version 25.2(v4.10.1), should assess exposure and prioritize patch application to prevent potential session data exposure.

Why it matters

CVE-2025-13478 is a high-severity vulnerability in OpenText Identity Manager that allows remote authenticated users to obtain another user's session data. Defenders should prioritize patch application and configuration review to prevent potential session data exposure.

  • Potential exposure of user session data
  • Need for patch application to prevent vulnerability exploitation
  • Importance of verifying Identity Manager configurations for secure cache handling
  • Potential impact on user session security

Technical summary

A cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).

Defensive priority

Defenders should prioritize verifying and applying patches for OpenText Identity Manager versions 25.2(v4.10.1) to prevent potential session data exposure.

Recommended defensive actions

  • Verify and apply patches for OpenText Identity Manager version 25.2(v4.10.1)
  • Review and update Identity Manager configurations to ensure secure cache handling
  • Monitor for potential session data exposure

Evidence notes

The CVE record and NVD entry provide details on a cache misconfiguration vulnerability in OpenText Identity Manager. However, the corpus lacks specific information on exploitation, impact, and remediation beyond patch application.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-13478 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-13478

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-13478 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13478

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.