VDB

GCVE-110-NCSC-2025-395

GCVE-110-NCSC-2025-395
Advisory PublishedCVSS 9.9/10
Vulnetix · Advisory published December 12, 2025
Multiple denial of service (DoS) vulnerabilities have been identified in Oracle Application Testing Suite, Apache Commons FileUpload, and SAP Business Objects, affecting various versions and allowing potential exploitation by attackers.

Weaknesses (CWE)

CWE-94Improper Control of Generation of Code ('Code Injection')CWE-150Improper Neutralization of Escape, Meta, or Control SequencesCWE-502Deserialization of Untrusted DataCWE-1244Internal Asset Exposed to Unsafe Debug Access Level or StateCWE-405Asymmetric Resource Consumption (Amplification)CWE-770Allocation of Resources Without Limits or ThrottlingCWE-787Out-of-bounds WriteCWE-306Missing Authentication for Critical FunctionCWE-549Missing Password Field MaskingCWE-489Active Debug CodeCWE-862Missing AuthorizationCWE-116Improper Encoding or Escaping of Output

Risk Scores

CVSS 3.1
9.9/10
Critical · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
SAPvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›