In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
History

Tue, 12 Aug 2025 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Xerox
Xerox freeflow Core
Vendors & Products Xerox
Xerox freeflow Core

Fri, 08 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
Description In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
Title Path Traversal leading to RCE
Weaknesses CWE-22
CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xerox

Published: 2025-08-08T15:40:12.588Z

Updated: 2025-08-08T15:49:27.895Z

Reserved: 2025-07-30T13:54:05.676Z

Link: CVE-2025-8356

cve-icon Vulnrichment

Updated: 2025-08-08T15:49:21.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-08T16:15:28.063

Modified: 2025-08-08T20:30:18.180

Link: CVE-2025-8356

cve-icon Redhat

No data.