VDB
GCVE-110-NCSC-2025-333
GCVE-110-NCSC-2025-333
Advisory PublishedCVSS 8.2/10
Multiple vulnerabilities in Oracle Financial Services applications and Apache XmlGraphics Commons allow unauthorized access to critical data and server-side request forgery, all with a CVSS score of 8.2.
Weaknesses (CWE)
CWE-862Missing AuthorizationCWE-918Server-Side Request Forgery (SSRF)CWE-611Improper Restriction of XML External Entity ReferenceCWE-400Uncontrolled Resource ConsumptionCWE-197Numeric Truncation ErrorCWE-23Relative Path TraversalCWE-20Improper Input ValidationCWE-1284Improper Validation of Specified Quantity in InputCWE-285Improper AuthorizationCWE-674Uncontrolled RecursionCWE-770Allocation of Resources Without Limits or ThrottlingCWE-404Improper Resource Shutdown or ReleaseCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-284Improper Access ControlCWE-306Missing Authentication for Critical Function
Risk Scores
CVSS 3.1
8.2/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle | vers:unknown/* | — | — |
Aliases
CVE-2020-11988CVE-2024-28168CVE-2025-27553CVE-2025-27817CVE-2025-31672CVE-2025-32415CVE-2025-41249CVE-2025-48924CVE-2025-48976CVE-2025-48989CVE-2025-50074CVE-2025-50075CVE-2025-5115CVE-2025-53034CVE-2025-53035CVE-2025-53036CVE-2025-53037CVE-2025-55163CVE-2025-59375CVE-2025-61751CVE-2025-61756CVE-2025-6965
Browse GCVE Records
73,877 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.