Metrics
Affected Vendors & Products
Solution
Upgrade to Axxon One 2.0.2 or later, where LDAP resolution logic was updated to recursively parse and flatten nested group structures before evaluating role binding. Ensure external LDAP directory structures are regularly audited for correct nesting and role mapping.
Workaround
No workaround given by the vendor.
Wed, 10 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 10 Sep 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One 2.0.2 and earlier on Windows allows a remote authenticated user to be denied access or misassigned roles via incorrect evaluation of nested LDAP group memberships during login. | |
Title | Incorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-09-10T13:13:47.948Z
Reserved: 2025-09-10T12:35:55.091Z
Link: CVE-2025-10224

Updated: 2025-09-10T13:13:32.195Z

Status : Received
Published: 2025-09-10T13:15:36.220
Modified: 2025-09-10T13:15:36.220
Link: CVE-2025-10224

No data.

No data.