PT-2025-37045 · Axxonsoft+1 · Axxonone+1
Published
2025-09-10
·
Updated
2025-12-19
·
CVE-2025-10226
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
AxxonSoft Axxon One versions 2.0.8 and earlier
Description:
AxxonSoft Axxon One is affected by a dependency on a vulnerable third-party component, PostgreSQL. This allows a remote attacker to escalate privileges, execute arbitrary code, or cause a denial-of-service by exploiting known vulnerabilities present in PostgreSQL v10.x. These vulnerabilities are resolved in PostgreSQL 17.4.
Recommendations:
Versions prior to PostgreSQL 17.4 are vulnerable.
Update PostgreSQL to version 17.4 or later.
Fix
DoS
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axxonone
Postgresql