LiveActive security incident?Get immediate response
CVE Record

CVE-2023-42344: Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a...

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2023-42344 affects Alkacon OpenCms versions before 10.5.1. A remote unauthenticated attacker could use an XXE flaw in a CMIS-related endpoint to obtain sensitive information. There is no source evidence of active exploitation, but the issue is important for any internet-facing OpenCms deployment.

Executive priority

Prioritize remediation for internet-facing OpenCms systems. The issue allows unauthenticated information disclosure, and public technical details are available. Internal-only or inaccessible instances are lower priority but should still be inventoried and upgraded according to vendor guidance.

Technical view

The CVE describes an XML External Entity issue reachable through the cmis-online/query path on a Chemistry servlet in OpenCms before 10.5.1. The reported impact is sensitive information disclosure by remote unauthenticated attackers. CVE metadata does not include CVSS, CWE, CPE, or detailed affected-version records.

Likely exposure

Organizations running OpenCms before 10.5.1 are most exposed, especially if the CMIS online servlet is reachable from untrusted networks. Exposure is less likely where OpenCms is not deployed, the affected endpoint is unavailable, or access is tightly restricted.

Exploitation context

The source bundle does not show CISA KEV listing or confirmed active exploitation. A public technical write-up exists, and the CVE states remote unauthenticated access is possible, so defenders should assume discovery and attempted probing are plausible.

Researcher notes

Evidence is sparse. The CVE record names OpenCms before 10.5.1 and the cmis-online/query Chemistry servlet, but lacks CVSS, CWE, and structured affected CPEs. Avoid assuming broader impact beyond OpenCms and validate against vendor documentation and deployment configuration.

Mitigation direction

  • Upgrade OpenCms to 10.5.1 or later where applicable.
  • Review Alkacon/OpenCms vendor guidance for definitive fixed versions and configuration advice.
  • Restrict untrusted access to CMIS-related OpenCms endpoints until remediated.
  • Monitor web logs for unusual requests to cmis-online/query.

Validation and detection

  • Identify all OpenCms deployments and record their versions.
  • Confirm whether any instance is below 10.5.1.
  • Check whether cmis-online/query is reachable from untrusted networks.
  • Review application and proxy logs for requests to CMIS endpoints.
  • Verify remediation by confirming the deployed version is 10.5.1 or later.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-42344 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
2Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.