CVE-2025-8386 - CERT CVE
ID CVE-2025-8386
Sažetak The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected.
Reference
CVSS
Base: 6.9
Impact: 5.3
Exploitability:1.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L
Zadnje važnije ažuriranje 15-11-2025 - 00:15
Objavljeno 15-11-2025 - 00:15