PT-2025-51834 · Netaxis · Netaxis Api Orchestrator

CVE-2022-23851

·

Published

2025-12-17

·

Updated

2025-12-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netaxis API Orchestrator (APIO) versions prior to 0.19.3
Description The Netaxis API Orchestrator (APIO) software contains a flaw that permits server side template injection (SSTI). This issue could potentially allow an attacker to execute arbitrary code on the server.
Recommendations Update Netaxis API Orchestrator (APIO) to version 0.19.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23851

Affected Products

Netaxis Api Orchestrator