open-text-corporationCVE-2026-12559
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application.
High7.3CVE-2026-12559 · Published Sep 24, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Vendor Invoice Management for SAP Solutions Vendor | >= VIM 7.6/20.4, <= 0009 | No fix yet |
| >= VIM 23.4, <= 0004 | No fix yet | |
| >= VIM 25.4, <= 0001 | No fix yet |
Details and references
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Red
- Severity from
- no source yet
- Weakness
- CWE-79
More open-text-corporation advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 9 | Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS CVE-2025-3271Medium4.8fixed in Documentum Webtop 16.7.1 | Medium4.8 | Documentum Webtop 16.7.1 |
| Aug 17 | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. CVE-2026-13202High7.3no fix yet | High7.3 | No fix yet |