Impact
The vulnerability results from failure to encode user‑supplied input used in an HTML attribute context during the authentication redirect flow. An attacker may craft a URL that, when loaded by an authenticated Teamcenter user, injects malicious JavaScript. This leads to cross‑site scripting that can execute code in the victim’s browser and allow the attacker to perform arbitrary actions within that user’s Teamcenter session, effectively compromising confidentiality, integrity, and session identity for that user.
Affected Systems
The flaw affects Siemens Teamcenter versions prior to V2412.0013, V2506.0010, V2512.2607, and V2606.2607. These include Teamcenter V2412, V2506, V2512, and V2606.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. No EPSS score is available, but the lack of a KEV listing suggests no publicly known exploits at this time. The attack vector, inferred from the description, is unauthenticated remote via crafted URL targeting the authentication redirect endpoint. The vulnerability requires the victim to load the malicious URL in a browser while authenticated, and it does not need any privileged access or local code. Therefore, remote attackers could exploit many exposed installations if the endpoint remains accessible to unauthenticated traffic.
OpenCVE Enrichment