CVE-2025-12455 PUBLISHED

Username Enumeration Observable Response Discrepancy vulnerability has been discovered in OpenText™ Vertica.

Assigner: OpenText
Reserved: 28.10.2025 Published: 13.03.2026 Updated: 13.03.2026

Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.   The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/S:N/AU:Y/R:U
CVSS Score: 5.1

Product Status

Vendor OpenText™
Product Vertica
Versions Default: unaffected
  • affected from 10.0 to 10.x (incl.)
  • affected from 11.0 to 11.x (incl.)
  • affected from 12.0 to 12.x (incl.)

Solutions

https://portal.microfocus.com/s/article/KM000045854?language=en_US

References

Problem Types

  • CWE-204 Observable response discrepancy CWE

Impacts

  • CAPEC-49 Password Brute Forcing