---
id: CVE-2025-13478
title: >-
  Cache misconfiguration vulnerability in OpenText Identity Manager on Windows,
  Linux allows remote authenticated users to obtain another user's session data
  via insecure application cache handling
summary: >-
  Cache misconfiguration vulnerability in OpenText Identity Manager on Windows,
  Linux allows remote authenticated users to obtain another user's session data
  via insecure application cache handling. This issue affects Identity Manager:
  25.…
severity: none
cwe:
  - CWE-522
published: '2026-03-27'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13478'
references:
  - url: 'https://docs.microfocus.com/doc/2159/25.2/cvesecurityfix'
    label: security@opentext.com
  - url: >-
      https://docs.microfocus.com/doc/2159/25.2/releasenotesidentitymanager4101patch01
    label: security@opentext.com
tags:
  - nvd
epss: 0.00286
epssPercentile: 0.19087
ingestedAt: '2026-09-30T22:27:27.742Z'
---

## Overview

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
