Cross-Site Scripting Vulnerability in OpenText™ Vertica Management Console
CVE-2025-12454

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2025-12454?

An improper input neutralization flaw in the OpenText™ Vertica management console allows for reflected cross-site scripting (XSS) attacks. By exploiting this vulnerability, an attacker could inject malicious scripts into web pages generated by the application, potentially compromising user sessions or redirecting users to malicious websites. This issue affects multiple versions of Vertica from 10.0 to 25.1.x, emphasizing the need for timely updates and security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Vertica 10.0 <= 10.x

Vertica 11.0 <= 11.x

Vertica 12.0 <= 12.x

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.