CVE-2025-13478: Opentext Identity Manager
High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).
Affected products
- Opentext Identity Manager: version 25.2(v4.10.1) only
Published 2026-03-27. Last modified 2026-10-07.