There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12465 There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
Fixes

Solution

6.1.03.11,7.2.01.01P1,Lite7.2.01.01P1


Workaround

No workaround given by the vendor.

History

Mon, 12 May 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxcloud Goldendb
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:zte:zxcloud_goldendb:6.1.03.09:*:*:*:*:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:6.1.03.10:*:*:*:*:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:-:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:lite:*:*:*
Vendors & Products Zte
Zte zxcloud Goldendb

Mon, 28 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Apr 2025 01:45:00 +0000

Type Values Removed Values Added
Description There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
Title ZTE GoldenDB Database product has a privilege escalation vulnerability
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2025-04-28T15:34:04.600Z

Reserved: 2025-04-25T00:28:13.908Z

Link: CVE-2025-46576

cve-icon Vulnrichment

Updated: 2025-04-28T13:42:44.685Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-27T02:15:15.830

Modified: 2025-05-12T19:32:59.980

Link: CVE-2025-46576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.