Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27538 | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4. |
Solution
Upgrade bundled or external PostgreSQL instances to v17.4 or later, which addresses all known CVEs up to that release and strengthens DB hardening.
Workaround
For environments unable to upgrade immediately, limit database exposure (network segmentation, firewalling). Regularly monitor PostgreSQL security advisories for backported patches.
Wed, 08 Oct 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4. | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4. |
| Title | PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One 2.0.8 and earlier to Address Multiple Vulnerabilities | PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilities |
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axxonsoft
Axxonsoft axxon One Linux Linux linux Microsoft Microsoft windows |
|
| Vendors & Products |
Axxonsoft
Axxonsoft axxon One Linux Linux linux Microsoft Microsoft windows |
Wed, 10 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4. | |
| Title | PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One 2.0.8 and earlier to Address Multiple Vulnerabilities | |
| Weaknesses | CWE-1395 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-10-08T11:56:42.741Z
Reserved: 2025-09-10T12:37:44.975Z
Link: CVE-2025-10226
Updated: 2025-09-10T13:11:09.897Z
Status : Awaiting Analysis
Published: 2025-09-10T13:15:36.650
Modified: 2025-10-08T12:15:35.727
Link: CVE-2025-10226
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:30Z
EUVD