216.73.216.233

CVE-2025-10226

· Published 10/09/2025 13:15 · Modified 10/09/2025 13:15

Labels: CVE-2025-10226 15ede60e-6fda-426e-be9c-e788f151a3772025-09-10CVE-2025-10226

Essential information

Published
10/09/2025 13:15
Modified
10/09/2025 13:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
15ede60e-6fda-426e-be9c-e788f151a377
NVD
View on NVD

Affected products (CPE)

ProductCPE
axxonsoft / axxon one cpe:2.3:a:axxonsoft:axxon_one:2.0.8:*:*:*:*:*:*:*
postgresql / postgresql cpe:2.3:a:postgresql:postgresql:<17.4:*:*:*:*:*:*:*

References