---
id: CVE-2023-7249
title: >-
  Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  vulnerability in OpenText OpenText Directory Services allows Path
  Traversal.This issue affects OpenText Directory Services: from 16.4.2 before
  24.1.
summary: >-
  Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  vulnerability in OpenText OpenText Directory Services allows Path
  Traversal.This issue affects OpenText Directory Services: from 16.4.2 before
  24.1.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: opentext
product: directory_services
affected:
  - 'directory_services >= 16.4.2, < 24.1'
patched:
  - directory_services 24.1
published: '2024-08-12'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-7249'
references:
  - url: >-
      https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0807814
    label: security@opentext.com
tags:
  - nvd
epss: 0.0058
epssPercentile: 0.45291
ingestedAt: '2026-09-03T02:54:37.624Z'
---

## Overview

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

## Affected

- `directory_services >= 16.4.2, < 24.1`

## Remediation

Upgrade past the affected range:

- `directory_services 24.1`
