CVE-2023-42344: Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a...
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
Security readout for executives and security teams
Plain-English summary
CVE-2023-42344 affects Alkacon OpenCms versions before 10.5.1. A remote unauthenticated attacker could use an XXE flaw in a CMIS-related endpoint to obtain sensitive information. There is no source evidence of active exploitation, but the issue is important for any internet-facing OpenCms deployment.
Executive priority
Prioritize remediation for internet-facing OpenCms systems. The issue allows unauthenticated information disclosure, and public technical details are available. Internal-only or inaccessible instances are lower priority but should still be inventoried and upgraded according to vendor guidance.
Technical view
The CVE describes an XML External Entity issue reachable through the cmis-online/query path on a Chemistry servlet in OpenCms before 10.5.1. The reported impact is sensitive information disclosure by remote unauthenticated attackers. CVE metadata does not include CVSS, CWE, CPE, or detailed affected-version records.
Likely exposure
Organizations running OpenCms before 10.5.1 are most exposed, especially if the CMIS online servlet is reachable from untrusted networks. Exposure is less likely where OpenCms is not deployed, the affected endpoint is unavailable, or access is tightly restricted.
Exploitation context
The source bundle does not show CISA KEV listing or confirmed active exploitation. A public technical write-up exists, and the CVE states remote unauthenticated access is possible, so defenders should assume discovery and attempted probing are plausible.
Researcher notes
Evidence is sparse. The CVE record names OpenCms before 10.5.1 and the cmis-online/query Chemistry servlet, but lacks CVSS, CWE, and structured affected CPEs. Avoid assuming broader impact beyond OpenCms and validate against vendor documentation and deployment configuration.
Mitigation direction
Upgrade OpenCms to 10.5.1 or later where applicable.
Review Alkacon/OpenCms vendor guidance for definitive fixed versions and configuration advice.
Restrict untrusted access to CMIS-related OpenCms endpoints until remediated.
Monitor web logs for unusual requests to cmis-online/query.
Validation and detection
Identify all OpenCms deployments and record their versions.
Confirm whether any instance is below 10.5.1.
Check whether cmis-online/query is reachable from untrusted networks.
Review application and proxy logs for requests to CMIS endpoints.
Verify remediation by confirming the deployed version is 10.5.1 or later.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2023-42344 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
2Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
May 8, 2026, 00:00 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.