PT-2025-30084 · Agorum Software Gmbh · Agorum Core

Dr

+5

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-52163

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions agorum Software GmbH Agorum core open versions 11.9.2 and 11.10.1
Description A Server-Side Request Forgery (SSRF) exists in the TunnelServlet component. This allows attackers to initiate connections to arbitrary internal and external resources using a crafted request, potentially leading to sensitive data exposure.
Recommendations Update to a newer version that resolves this issue. As a temporary workaround, consider restricting network access for the TunnelServlet component to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-52163

Affected Products

Agorum Core