Metrics
Affected Vendors & Products
Solution
Upgrade bundled or external PostgreSQL instances to v17.4 or later, which addresses all known CVEs up to that release and strengthens DB hardening.
Workaround
For environments unable to upgrade immediately, limit database exposure (network segmentation, firewalling). Regularly monitor PostgreSQL security advisories for backported patches.
Wed, 10 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 10 Sep 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4. | |
Title | PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One 2.0.8 and earlier to Address Multiple Vulnerabilities | |
Weaknesses | CWE-1395 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-09-10T13:11:16.308Z
Reserved: 2025-09-10T12:37:44.975Z
Link: CVE-2025-10226

Updated: 2025-09-10T13:11:09.897Z

Status : Received
Published: 2025-09-10T13:15:36.650
Modified: 2025-09-10T13:15:36.650
Link: CVE-2025-10226

No data.

No data.