Improper input validation in Oracle Commerce Platform - CVE-2025-48795

 

Improper input validation in Oracle Commerce Platform - CVE-2025-48795

Published: October 22, 2025


Vulnerability identifier: #VU117439
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48795
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to read and manipulate data.

The vulnerability exists due to improper input validation within the Endeca Integration (Apache CXF) component in Oracle Commerce Platform. A remote privileged user can exploit this vulnerability to read and manipulate data.


Affected software

Oracle Commerce Platform
IBM Sterling File Gateway
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
Oracle WebCenter Forms Recognition
Primavera P6 Enterprise Project Portfolio Management
Oracle BI Publisher
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
Oracle Banking Liquidity Management
Oracle Banking Cash Management
Oracle Communications Cloud Native Core Unified Data Repository

How to mitigate CVE-2025-48795

Install updates from vendor's website.

IBM Sterling File Gateway - addressed in versions 6.1.2.7.2, 6.2.0.5.1, 6.2.1.1.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7.2, 6.2.0.5.1, 6.2.1.1.1
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Maximo Application Suite - Monitor Component - addressed in versions 8.10.25, 8.11.23, 9.0.15, 9.1.5
DevOps Test Performance - update to 11.0.8

External References

Related Security Bulletins