VYPR
Low severityNVD Advisory· Published Nov 19, 2025· Updated Apr 15, 2026

CVE-2025-11884

CVE-2025-11884

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The vulnerability could allow an attacker has high level access to UCMDB to create or update data with malicious scripts

This issue affects uCMDB: 24.4.

Affected products

2
  • Ucmdb/Ucmdbinferred2 versions
    = 24.4+ 1 more
    • (no CPE)range: = 24.4
    • (no CPE)range: =24.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.