Executive brief
Documentum Webtop is an enterprise document management interface used by organizations to access and manage documents in their Documentum repositories. Versions before 16.7.1 contain a cross-site scripting (XSS) vulnerability that could allow an attacker to inject malicious scripts, potentially compromising user sessions, stealing credentials, or redirecting users to malicious sites.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in Documentum Webtop versions prior to 16.7.1. The root cause involves insufficient input validation or output encoding in user-controllable input fields. An attacker can inject malicious JavaScript code through a crafted request, which executes in the context of a victim's browser session when they access the application. The attack typically requires social engineering (e.g., sending a malicious link) or network positioning to deliver the payload. Exploitation can lead to session hijacking, credential theft, or malware distribution. The vulnerability is addressed in version 16.7.1 and later.
Affected products
- OpenText Documentum Webtop prior to 16.7.1
Timeline
- 2026-09-09: disclosed