Improper input validation in Oracle Communications Cloud Native Core Network Function Cloud Native Environment - CVE-2025-53547

 

Improper input validation in Oracle Communications Cloud Native Core Network Function Cloud Native Environment - CVE-2025-53547

Published: October 22, 2025


Vulnerability identifier: #VU117441
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53547
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Configuration (Helm) component in Oracle Communications Cloud Native Core Network Function Cloud Native Environment. A local non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Communications Cloud Native Core Network Function Cloud Native Environment
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Package Hub 15
Containers Module
openSUSE Leap
Siebel CRM Cloud Applications
Astronomer with IBM
Multicluster Engine for Kubernetes
Red Hat Advanced Cluster Management for Kubernetes
helm-debuginfo
helm
helm-fish-completion
helm-zsh-completion
helm-bash-completion

How to mitigate CVE-2025-53547

Install updates from vendor's website.

Astronomer with IBM - update to 1.1.0
Multicluster Engine for Kubernetes - update to 2.7.6
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
helm-debuginfo - update to 3.19.1-150000.1.57.1
helm - update to 3.19.1-150000.1.57.1
helm-fish-completion - update to 3.19.1-150000.1.57.1
helm-zsh-completion - update to 3.19.1-150000.1.57.1
helm-bash-completion - update to 3.19.1-150000.1.57.1

External References

Related Security Bulletins