CVE-2025-11843
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-31

Last updated on: 2025-11-04

Assigner: Canon_EMEA

Description
Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API when connecting to the Therefore™ Server. If the malicious user gains this impersonation user access, then it is possible for them to access the documents stored in Therefore™. This impersonation is at application level (Therefore access level), not the operating system level.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-31
Last Modified
2025-11-04
Generated
2026-06-16
AI Q&A
2025-10-31
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
therefore therefore_online *
therefore therefore_on-premises *
therefore therefore_server *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an account impersonation issue in Therefore™ Online and Therefore™ On-Premises. A malicious user may be able to impersonate the web service account or a service account using the API when connecting to the Therefore™ Server. This allows the attacker to access documents stored in Therefore™ at the application level, not at the operating system level.

Impact Analysis

If exploited, this vulnerability could allow an attacker to gain unauthorized access to documents stored in Therefore™, potentially leading to data exposure or data breaches within the application environment.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-11843. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart