PT-2025-51834 · Netaxis · Netaxis Api Orchestrator

Published

2025-12-17

·

Updated

2025-12-22

·

CVE-2022-23851

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netaxis API Orchestrator (APIO) versions prior to 0.19.3
Description The Netaxis API Orchestrator (APIO) software contains a flaw that permits server side template injection (SSTI). This issue could potentially allow an attacker to execute arbitrary code on the server.
Recommendations Update Netaxis API Orchestrator (APIO) to version 0.19.3 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-23851

Affected Products

Netaxis Api Orchestrator