VDB
GCVE-110-NCSC-2025-395
GCVE-110-NCSC-2025-395
Advisory PublishedCVSS 9.9/10
Multiple denial of service (DoS) vulnerabilities have been identified in Oracle Application Testing Suite, Apache Commons FileUpload, and SAP Business Objects, affecting various versions and allowing potential exploitation by attackers.
Weaknesses (CWE)
CWE-94Improper Control of Generation of Code ('Code Injection')CWE-150Improper Neutralization of Escape, Meta, or Control SequencesCWE-502Deserialization of Untrusted DataCWE-1244Internal Asset Exposed to Unsafe Debug Access Level or StateCWE-405Asymmetric Resource Consumption (Amplification)CWE-770Allocation of Resources Without Limits or ThrottlingCWE-787Out-of-bounds WriteCWE-306Missing Authentication for Critical FunctionCWE-549Missing Password Field MaskingCWE-489Active Debug CodeCWE-862Missing AuthorizationCWE-116Improper Encoding or Escaping of Output
Risk Scores
CVSS 3.1
9.9/10
Critical · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| SAP | vers:unknown/* | — | — |
Browse GCVE Records
73,877 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.