VDB
WID-SEC-W-2025-2360
WID-SEC-W-2025-2360
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Communications Applications umfasst eine Sammlung von Werkzeugen zur Verwaltung von Messaging-, Kommunikationsdiensten und -ressourcen.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Communications Applications 15.1.0.0.0 | ||
| Oracle Communications Applications 15.0.1.0.0 | ||
| Oracle Communications Applications <=7.8.0 | ||
| Oracle Communications Applications <=12.0.6.0.0 | ||
| Oracle Communications Applications 3.0.3.4.0 | ||
| Oracle Communications Applications <=15.0.1.0.0 | ||
| Oracle Communications Applications <=2.0.0.1.0 | ||
| Oracle Communications Applications 2.0.0.1.0 | ||
| Oracle Communications Applications 8.0.0.8.0 | ||
| Oracle Communications Applications 8.1.0.28 | ||
| Oracle Communications Applications 8.0.0.9.0 | ||
| Oracle Communications Applications 2.0.0.0.0 | ||
| Oracle Communications Applications <=6.1.1 | ||
| Oracle Communications Applications 7.4.0 | ||
| Oracle Communications Applications 12.0.6.0.0 |
Exploit Intelligence
- Apache's commons-lang2 v2.6 with a backported fix for CVE-2025-48924 (github-poc)
- CVE-2025-27817 (github-poc)
- CVE‑2025‑4517 Proof‑of‑Concept Script (github-poc-repo)
- CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile` (github-poc-repo)
- Python tarfile data filter bypass via PATH_MAX overflow in os.path.realpath() - CVE-2025-4517 / CVE-2025-4330 (github-poc-repo)
- CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass (github-poc-repo)
- A Python script to generate a malicious tar archive that exploits CVE-2025-4138 / CVE-2025-4517. (github-poc-repo)
- PoC and explanation for CVE-2025-4517 used in a CTF I was playing. (github-poc-repo)
- Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow (github-poc-repo)
- Path traversal vulnerability in Python's tarfile. (github-poc-repo)
…and 92 more exploits
Timeline
- Oct 21, 2025 CVE Published
- Nov 17, 2025 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2360.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2360 advisory
- https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixCAGBU url
- https://security.business.xerox.com/wp-content/uploads/2025/11/Xerox-Security-Bulletin-XRX25-018-Xerox-FreeFlow-Print-Server-v7.pdf url