PT-2025-43989 · Bae Systems · Socet Gxp
Published
2025-10-27
·
Updated
2025-10-27
·
CVE-2025-54969
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
BAE SOCET GXP versions prior to 4.6.0.2
Description
The SOCET GXP Job Status Service lacks Cross-Site Request Forgery (CSRF) protections. An attacker could potentially trick a legitimate user into unknowingly submitting requests to the Job Status Service by exploiting a malicious link or website. This could allow the attacker to perform actions as the user without their consent.
Recommendations
Update BAE SOCET GXP to version 4.6.0.2 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Socet Gxp