# CVE-2024-12799

## Summary

- **CVE ID:** CVE-2024-12799
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:H/U:Red)
- **CWE:** CWE-522
- **Published:** Mar 5, 2025
- **Last Modified:** Mar 13, 2026

## Description

Insufficiently Protected Credentials
vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux,
64 bit allows Privilege Abuse. This vulnerability could allow an
authenticated user to obtain higher privileged user’s sensitive information via
crafted payload.

This issue affects Identity Manager Advanced
Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.

## Affected Products

- OpenText — Identity Manager Advanced Edition (4.8.0.0)
- OpenText — Identity Manager Advanced Edition (4.9.0.0)

## References

- [CNA](https://portal.microfocus.com/s/article/KM000037455)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._