CVE-2026-12559
7.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Red
Summary
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenText | Vendor Invoice Management for SAP Solutions | VIM 7.6/20.4 <= 0009 | affected |
| OpenText | Vendor Invoice Management for SAP Solutions | VIM 23.4 <= 0004 | affected |
| OpenText | Vendor Invoice Management for SAP Solutions | VIM 25.4 <= 0001 | affected |
Weaknesses
- CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0869044
- https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0869040
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.