An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information without the permissions of the job owner.
References
| Link | Resource |
|---|---|
| https://www.baesystems.com/en-us/product/geospatial-exploitation-products | Product |
| https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 | Vendor Advisory Mitigation |
Configurations
History
31 Oct 2025, 20:29
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:baesystems:socet_gxp:*:*:*:*:*:*:*:* | |
| References | () https://www.baesystems.com/en-us/product/geospatial-exploitation-products - Product | |
| References | () https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 - Vendor Advisory, Mitigation | |
| First Time |
Baesystems
Baesystems socet Gxp |
Information
Published : 2025-10-27 17:15
Updated : 2025-10-31 20:29
NVD link : CVE-2025-54970
Mitre link : CVE-2025-54970
CVE.ORG link : CVE-2025-54970
JSON object : View
Products Affected
baesystems
- socet_gxp
CWE
CWE-284
Improper Access Control
