VDB

GCVE-110-NCSC-2025-333

GCVE-110-NCSC-2025-333
Advisory PublishedCVSS 8.2/10
Vulnetix · Advisory published October 23, 2025
Multiple vulnerabilities in Oracle Financial Services applications and Apache XmlGraphics Commons allow unauthorized access to critical data and server-side request forgery, all with a CVSS score of 8.2.

Weaknesses (CWE)

CWE-862Missing AuthorizationCWE-918Server-Side Request Forgery (SSRF)CWE-611Improper Restriction of XML External Entity ReferenceCWE-400Uncontrolled Resource ConsumptionCWE-197Numeric Truncation ErrorCWE-23Relative Path TraversalCWE-20Improper Input ValidationCWE-1284Improper Validation of Specified Quantity in InputCWE-285Improper AuthorizationCWE-674Uncontrolled RecursionCWE-770Allocation of Resources Without Limits or ThrottlingCWE-404Improper Resource Shutdown or ReleaseCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-284Improper Access ControlCWE-306Missing Authentication for Critical Function

Risk Scores

CVSS 3.1
8.2/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›