CyberRota Analysis
AI-GeneratedTeamcenter versions prior to V2412.0013, V2506.0010, V2512.2607, and V2606.2607 are vulnerable due to improper encoding of user-supplied input in the authentication redirect flow, specifically at the /auth/ endpoint. This flaw allows unauthenticated remote attackers to inject arbitrary JavaScript into the browsers of authenticated users, potentially compromising their Teamcenter sessions. Organizations using affected versions should prioritize patching to mitigate the risk of session hijacking and unauthorized actions.
Original NVD Description
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.