CVE-2026-12559: Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.
Affected Software
Event History
Frequently Asked Questions
Which product versions are affected?
The provided advisory data does not identify affected or fixed versions. The referenced OpenText knowledge-base articles are the available source for version-specific guidance.
Is a default deployment known to be affected?
The available information does not state whether the vulnerability is reachable or exploitable in a default configuration. It only notes that exploitation is possible under certain conditions.
How can administrators determine whether exploitation has occurred?
The provided information does not include indicators of compromise, logging guidance, or detection steps for this issue.