CVE-2025-12454

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*

History

17 Apr 2026, 15:23

Type Values Removed Values Added
Summary
  • (es) Neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting') vulnerabilidad en OpenText™ Vertica permite XSS Reflejado. La vulnerabilidad podría conducir a un ataque de XSS Reflejado de cross-site scripting en la aplicación de consola de gestión de Vertica. Este problema afecta a Vertica: desde 10.0 hasta 10.X, desde 11.0 hasta 11.X, desde 12.0 hasta 12.X, desde 23.0 hasta 23.X, desde 24.0 hasta 24.X, desde 25.1.0 hasta 25.1.X.
CPE cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*
References () https://portal.microfocus.com/s/article/KM000045853?language=en_US - () https://portal.microfocus.com/s/article/KM000045853?language=en_US - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Opentext
Opentext vertica

13 Mar 2026, 19:53

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:53

Updated : 2026-04-17 15:23


NVD link : CVE-2025-12454

Mitre link : CVE-2025-12454

CVE.ORG link : CVE-2025-12454


JSON object : View

Products Affected

opentext

  • vertica
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')