# CVE-2025-13478

## Summary

- **CVE ID:** CVE-2025-13478
- **Severity:** HIGH
- **CVSS Score:** 8.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N)
- **CWE:** CWE-522
- **Published:** Mar 27, 2026
- **Last Modified:** Mar 27, 2026

## Description

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).

## Affected Products

- OpenText — Identity Manager (25.2(v4.10.1))

## References

- [CNA](https://docs.microfocus.com/doc/2159/25.2/cvesecurityfix)
- [CNA](https://docs.microfocus.com/doc/2159/25.2/releasenotesidentitymanager4101patch01)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._