PT-2025-37045 · Axxonsoft+1 · Axxonone+1

Published

2025-09-10

·

Updated

2025-12-19

·

CVE-2025-10226

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: AxxonSoft Axxon One versions 2.0.8 and earlier
Description: AxxonSoft Axxon One is affected by a dependency on a vulnerable third-party component, PostgreSQL. This allows a remote attacker to escalate privileges, execute arbitrary code, or cause a denial-of-service by exploiting known vulnerabilities present in PostgreSQL v10.x. These vulnerabilities are resolved in PostgreSQL 17.4.
Recommendations: Versions prior to PostgreSQL 17.4 are vulnerable. Update PostgreSQL to version 17.4 or later.

Fix

DoS

LPE

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10226

Affected Products

Axxonone
Postgresql