The vendor explicitly identifies these products as affected by this CVE.
- Teamcenter V2412 < V2412.0013
- Teamcenter V2506 < V2506.0010
- Teamcenter V2512 < V2512.2607
- Teamcenter V2606 < V2606.2607
- Summary
- Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
- Remediation
- Update to V2412.0013 or later version
