An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that will execute with the permissions of other users.
References
| Link | Resource |
|---|---|
| https://www.baesystems.com/en-us/product/geospatial-exploitation-products | Product |
| https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54968 | Vendor Advisory Mitigation |
Configurations
History
31 Oct 2025, 20:31
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.baesystems.com/en-us/product/geospatial-exploitation-products - Product | |
| References | () https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54968 - Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:baesystems:socet_gxp:*:*:*:*:*:*:*:* | |
| First Time |
Baesystems
Baesystems socet Gxp |
28 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
27 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 17:15
Updated : 2025-10-31 20:31
NVD link : CVE-2025-54968
Mitre link : CVE-2025-54968
CVE.ORG link : CVE-2025-54968
JSON object : View
Products Affected
baesystems
- socet_gxp
CWE
CWE-284
Improper Access Control
