CVE-2025-0883: vulnerability has been discovered in OpenText™ Service Manager.

2.1 CVSS

Description

Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager. 

The vulnerability could reveal sensitive information retained by the browser.

This issue affects Service Manager: 9.70, 9.71, 9.72, 9.80.

Classification

CVE ID: CVE-2025-0883

CVSS Base Severity: LOW

CVSS Base Score: 2.1

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/S:P/AU:N/R:A/V:C/RE:M/U:Green

Problem Types

CWE-81 Improper Neutralization of Script in an Error Message Web Page

Affected Products

Vendor: OpenText™

Product: Service Manager

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 10.4% (scored less or equal to compared to others)

EPSS Date: 2025-04-10 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-0883
https://portal.microfocus.com/s/article/KM000037099?language=en_US

Timeline