Description
Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS
Published: 2026-09-09
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Documentum Webtop versions before 16.7.1 contain a DOM‑based cross‑site scripting flaw that permits an attacker to inject and run arbitrary JavaScript when users access manipulated input or crafted URLs. The weakness, classified as CWE‑79, can lead to session hijacking, data theft, or other client‑side attacks.

Affected Systems

OpenText Documentum Webtop installations running any version earlier than 16.7.1.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. No EPSS value is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nonetheless, the flaw can be triggered remotely via a web‑based attack, such as redirecting a user to a malicious link that exploits the DOM XSS, enabling the attacker to execute code inside the victim’s browser and potentially steal session data or perform unauthorized actions.

Generated by OpenCVE AI on September 9, 2026 at 11:02 UTC.

Remediation

Vendor Solution

Upgrade to OpenText™ Documentum Webtop 16.7.1 or later.


OpenCVE Recommended Actions

  • Upgrade OpenText Documentum Webtop to version 16.7.1 or later.
  • Implement a strict content‑security policy that limits script sources to trusted origins.
  • Ensure that all user‑supplied data reflected in the DOM is properly sanitized and validated to prevent unsanitized input from reaching client‑side code.

Generated by OpenCVE AI on September 9, 2026 at 11:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS
Title DOM-based XSS vulnerability in OpenText™ Documentum Webtop
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2026-09-09T12:48:55.752Z

Reserved: 2025-04-04T13:39:26.386Z

Link: CVE-2025-3271

cve-icon Vulnrichment

Updated: 2026-09-09T12:48:28.763Z

cve-icon NVD

Status : Received

Published: 2026-09-09T10:17:02.617

Modified: 2026-09-09T13:17:26.890

Link: CVE-2025-3271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T11:15:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')