OpenText™ Vulnerabilities and Affected Products
Vulnerabilities associated with Vertica.
Products
Clear product- Vertica5 vulnerabilities
- Operations Bridge Manager4 vulnerabilities
- Directory Services3 vulnerabilities
- Exceed Turbo X3 vulnerabilities
- Web Site Management Server3 vulnerabilities
- Asset Management X (AMX)2 vulnerabilities
- Filr2 vulnerabilities
- Network Node Manager i (NNMi)2 vulnerabilities
- Service Management Automation X (SMAX)2 vulnerabilities
- Service Manager2 vulnerabilities
- XM Fax2 vulnerabilities
- AccuRev1 vulnerability
- ALM Octane Management1 vulnerability
- ALM Octane.1 vulnerability
- Application Lifecycle Management (ALM),Quality Center1 vulnerability
- Carbonite Safe Server Backup1 vulnerability
- Content Management (Extended ECM)1 vulnerability
- CX-E Voice1 vulnerability
- Digital Asset Management.1 vulnerability
- Documentum™ Server1 vulnerability
- GroupWise1 vulnerability
- Hybrid Cloud Management X (HCMX)1 vulnerability
- Operations Agent1 vulnerability
- Operations Bridge Suite (Containerized)1 vulnerability
- Solutions Business Manager (SBM)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-12453MEDIUM | Improper neutralization of input during web page generation vulnerability has been discovered in OpenText™ Vertica.Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X, from 25.2.0 through 25.2.X, from 25.3.0 through 25.3.X. CWE-79Mar 13, 2026 | CVSS5.1v4.0 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12454MEDIUM | Improper neutralization of input during web page generation vulnerability has been discovered in OpenText™ Vertica.Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X. CWE-79Mar 13, 2026 | CVSS5.1v4.0 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12455MEDIUM | Username Enumeration Observable Response Discrepancy vulnerability has been discovered in OpenText™ Vertica.Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X. CWE-204Mar 13, 2026 | CVSS5.1v4.0 | EPSS0.303% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9432MEDIUM | Cleartext Storage of Sensitive Information vulnerability has been discovered in OpenText™ Vertica.Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data. The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X. CWE-312Jan 30, 2026 | CVSS6.9v4.0 | EPSS0.091% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6360MEDIUM | Incorrect Permission Assignment for Critical Resource vulnerability has been discovered in OpenText™ Vertica.Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X. CWE-732Oct 2, 2024 | CVSS6.9v4.0 | EPSS0.308% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |