PT-2025-47533 · Opentext · Opentext Ucmdb

Published

2025-11-19

·

Updated

2025-11-20

·

CVE-2025-11884

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Green
Name of the Vulnerable Software and Affected Versions opentext uCMDB version 24.4
Description A flaw exists in opentext uCMDB that allows for Stored Cross-site Scripting (XSS). An attacker with high-level access to uCMDB can create or update data containing malicious scripts. The vulnerability arises from improper neutralization of input during web page generation.
Recommendations Update to a newer version that addresses this vulnerability. As a temporary workaround, carefully review and sanitize all data inputs before creation or updates within uCMDB. Restrict access to data creation and modification functionalities to only authorized personnel.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-11884

Affected Products

Opentext Ucmdb