CVE-2025-54966
BaseFortify
Publication date: 2025-10-23
Last updated on: 2025-10-28
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| baesystems | socet_gxp | to 4.6.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in BAE SOCET GXP before version 4.6.0.2 involves some endpoints of the SOCET GXP Job Status Service potentially returning sensitive information. This information can include local file paths and the SOCET GXP version details, which could be exposed in certain situations.
How can this vulnerability impact me? :
The impact of this vulnerability is that sensitive information such as local file paths and software version details may be exposed. This could potentially aid an attacker in further exploiting the system by providing insights into the environment and software configuration.