ENISA EUVD · EUVD-2025-18407Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-0162Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2768SAP Patchday Dezember 2025: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in SAP ausnutzen, um beliebigen Code auszuführen, Systeme zu übernehmen, sensible Daten abzuziehen, interne Ressourcen über SSRF anzusteuern, Dienste zum Absturz zu bringen oder Autorisierungsgrenzen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2025-2359Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2438Oracle Commerce: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Commerce ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1204Oracle Financial Services Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1194Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1118Dell PowerProtect Data Domain OS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain OS ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, um erweiterte Rechte zu erlangen – einschließlich Administratorrechte –, um Sicherheitsmaßnahmen zu umgehen, um Daten zu manipulieren, um vertrauliche Informationen offenzulegen oder um andere, nicht näher spezifizierte Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0438Atlassian Bamboo und Confluence (Data Center und Server): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Bamboo und Atlassian Confluence ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0177Atlassian Bamboo, Bitbucket, Confluence und Jira: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, und um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0175Oracle Supply Chain: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Supply Chain ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-0165Oracle Siebel CRM: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Siebel CRM ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-0163Oracle Financial Services Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-0153Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2361Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2360Oracle Communications Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2356Oracle Financial Services Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2373Oracle Retail Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Retail Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2366Oracle Hyperion: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Hyperion ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2369Oracle Utilities Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2362Oracle Insurance Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Insurance Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2357Oracle Commerce: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Commerce ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2353Oracle Construction and Engineering: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Construction and Engineering ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2853HCL Commerce: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in HCL Commerce ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Daten zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, und um Informationen offenzulegen.
Official advisory ↗BSI · German · WID-SEC-2025-2371Oracle Supply Chain: Schwachstelle gefährdet VerfügbarkeitEin entfernter, anonymer Angreifer kann eine Schwachstelle in Oracle Supply Chain ausnutzen, um die Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2355Oracle Enterprise Manager: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Enterprise Manager ausnutzen, um die Vertraulichkeit und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-1334Apache Commons FileUpload: Schwachstelle ermöglicht Denial of ServiceEin entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Commons FileUpload ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2025-2351Oracle REST Data Services: Schwachstelle gefährdet VerfügbarkeitEin entfernter, authentisierter Angreifer kann eine Schwachstelle in Oracle REST Data Services ausnutzen, um die Verfügbarkeit zu gefährden.
Official advisory ↗Canadian Centre for Cyber Security · English · AV26-218[Control systems] Hitachi security advisory (AV26-218)On March 10, 2026, Hitachi published a security advisory to address a vulnerability in the following products:
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0671Multiples vulnérabilités dans les produits NetAppDe multiples vulnérabilités ont été découvertes dans les produits NetApp. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0606Multiples vulnérabilités dans les produits IBMRecord?id=CVE-2025-2900
Référence CVE CVE-2025-30167
https://www.cve.org/CVERecord?id=CVE-2025-30167
Référence CVE CVE-2025-30698
https://www.cve.org/CVERecord?id=CVE-2025-30698
Référence CVE CVE-2025-30749
https://www.cve.org/CVERecord?id=CVE-2025-30749
Référence CVE CVE-2025-30754
https://www.cve.org/CVERecord?id=CVE-2025-30754
Référence CVE CVE-2025-30761
https://www.cve.org/CVERecord?id=CVE-2025-30761
Référence CVE CVE-2025-36126
https://www.cve.org/CVERecord?id=CVE-2025-36126
Référence CVE CVE-2025-3633
https://www.cve.org/CVERecord?id=CVE-2025-3633
Référence CVE CVE-2025-4447
https://www.cve.org/CVERecord?id=CVE-2025-4447
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-50059
https://www.cve.org/CVERecord?id=CVE-2025-50059
Référence CVE CVE-2025-50106
https://www.cve.org/CVERecord?id=CVE-2025-50106
Référence CVE CVE-2025-50181
https://www.cve.org/CVERecord?id=CVE-2025-50181
Référence CVE CVE-2025-50182
https://www.cve.org/CVERecord?id=CVE-2025-50182
Référence CVE CVE-2025-53057
https://www.cve.org/CVERecord?id=CVE-2025-53057
Référence CVE CVE-2025-53066
https://www.cve.org/CVERecord?id=CVE-2025-53066
Référence CVE CVE-2025-54798
https://www.cve.org/CVERecord?id=CVE-2025-54798
Référence CVE CVE-2025-56200
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0556Multiples vulnérabilités dans les produits VMware/CVERecord?id=CVE-2025-4207
Référence CVE CVE-2025-4330
https://www.cve.org/CVERecord?id=CVE-2025-4330
Référence CVE CVE-2025-4435
https://www.cve.org/CVERecord?id=CVE-2025-4435
Référence CVE CVE-2025-4516
https://www.cve.org/CVERecord?id=CVE-2025-4516
Référence CVE CVE-2025-4517
https://www.cve.org/CVERecord?id=CVE-2025-4517
Référence CVE CVE-2025-46392
https://www.cve.org/CVERecord?id=CVE-2025-46392
Référence CVE CVE-2025-47914
https://www.cve.org/CVERecord?id=CVE-2025-47914
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-48924
https://www.cve.org/CVERecord?id=CVE-2025-48924
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-49128
https://www.cve.org/CVERecord?id=CVE-2025-49128
Référence CVE CVE-2025-50077
https://www.cve.org/CVERecord?id=CVE-2025-50077
Référence CVE CVE-2025-50078
https://www.cve.org/CVERecord?id=CVE-2025-50078
Référence CVE CVE-2025-50079
https://www.cve.org/CVERecord?id=CVE-2025-50079
Référence CVE CVE-2025-50080
https://www.cve.org/CVERecord?id=CVE-2025-50080
Référence CVE CVE-2025-50082
https://www.cve.org/CVERecord?id=CVE-2025-50082
Référence CVE CVE-2025-50083
https://www.cve.org/CVERecord?id=CVE-2025-50083
Référence CVE CVE-2025-50084
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0322Multiples vulnérabilités dans les produits VMwared?id=CVE-2024-57699
Référence CVE CVE-2025-14831
https://www.cve.org/CVERecord?id=CVE-2025-14831
Référence CVE CVE-2025-15281
https://www.cve.org/CVERecord?id=CVE-2025-15281
Référence CVE CVE-2025-22228
https://www.cve.org/CVERecord?id=CVE-2025-22228
Référence CVE CVE-2025-22235
https://www.cve.org/CVERecord?id=CVE-2025-22235
Référence CVE CVE-2025-31650
https://www.cve.org/CVERecord?id=CVE-2025-31650
Référence CVE CVE-2025-31651
https://www.cve.org/CVERecord?id=CVE-2025-31651
Référence CVE CVE-2025-46701
https://www.cve.org/CVERecord?id=CVE-2025-46701
Référence CVE CVE-2025-48924
https://www.cve.org/CVERecord?id=CVE-2025-48924
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-48988
https://www.cve.org/CVERecord?id=CVE-2025-48988
Référence CVE CVE-2025-48989
https://www.cve.org/CVERecord?id=CVE-2025-48989
Référence CVE CVE-2025-49124
https://www.cve.org/CVERecord?id=CVE-2025-49124
Référence CVE CVE-2025-49125
https://www.cve.org/CVERecord?id=CVE-2025-49125
Référence CVE CVE-2025-52434
https://www.cve.org/CVERecord?id=CVE-2025-52434
Référence CVE CVE-2025-52520
https://www.cve.org/CVERecord?id=CVE-2025-52520
Référence CVE CVE-2025-53506
https://www.cve.org/CVERecord?id=CVE-2025-53506
Référence CVE CVE-2025-55668
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0292Multiples vulnérabilités dans les produits IBMd?id=CVE-2025-13723
Référence CVE CVE-2025-13726
https://www.cve.org/CVERecord?id=CVE-2025-13726
Référence CVE CVE-2025-14811
https://www.cve.org/CVERecord?id=CVE-2025-14811
Référence CVE CVE-2025-30749
https://www.cve.org/CVERecord?id=CVE-2025-30749
Référence CVE CVE-2025-30754
https://www.cve.org/CVERecord?id=CVE-2025-30754
Référence CVE CVE-2025-30761
https://www.cve.org/CVERecord?id=CVE-2025-30761
Référence CVE CVE-2025-41248
https://www.cve.org/CVERecord?id=CVE-2025-41248
Référence CVE CVE-2025-41249
https://www.cve.org/CVERecord?id=CVE-2025-41249
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-50059
https://www.cve.org/CVERecord?id=CVE-2025-50059
Référence CVE CVE-2025-50106
https://www.cve.org/CVERecord?id=CVE-2025-50106
Référence CVE CVE-2025-5115
https://www.cve.org/CVERecord?id=CVE-2025-5115
Référence CVE CVE-2025-53057
https://www.cve.org/CVERecord?id=CVE-2025-53057
Référence CVE CVE-2025-53066
https://www.cve.org/CVERecord?id=CVE-2025-53066
Gestion détaillée du document
le 13 mars 2026
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0182Multiples vulnérabilités dans Atlassian ConfluenceDe multiples vulnérabilités ont été découvertes dans Atlassian Confluence. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0074Multiples vulnérabilités dans Oracle WeblogicDe multiples vulnérabilités ont été découvertes dans Oracle Weblogic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0020Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0002Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1100Multiples vulnérabilités dans les produits AtlassianDe multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1079Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1051Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1034Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1025Multiples vulnérabilités dans les produits AtlassianDe multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une falsification de requêtes côté serveur (SSRF).
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1013Multiples vulnérabilités dans les produits IBMf de sécurité PH68266
Sterling Transformation Extender versions 10.1.1.1 sans le correctif de sécurité PH68266
Sterling Transformation Extender versions 10.1.2.1 sans le correctif de sécurité PH68266
Sterling Transformation Extender versions 11.0.0.0 sans le correctif de sécurité PH68266
Sterling Transformation Extender versions 11.0.1.1 sans le correctif de sécurité PH68819
Sterling Transformation Extender versions 11.0.2.0 sans le correctif de sécurité PH68819
Storage Protect Operations Center versions 8.1.x antérieures à 8.1.27.100
Tivoli Application Dependency Discovery Manager versions 7.3.x à 7.3.0.12 sans le correctif de sécurité efix_CVE-2025-48976_FP12250331.zip
WebSphere Application Server Liberty versions 17.0.0.3 à 25.0.0.11 sans le correctif de sécurité 25.0.0.12
WebSphere Application Server versions 8.5.x sans le correctif de sécurité 8.5.5.29
WebSphere Application Server versions 9.0.x sans le correctif de sécurité 9.0.5.27
Résumé
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentat
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0939Multiples vulnérabilités dans les produits SplunkCVERecord?id=CVE-2024-52533
Référence CVE CVE-2024-6763
https://www.cve.org/CVERecord?id=CVE-2024-6763
Référence CVE CVE-2025-22866
https://www.cve.org/CVERecord?id=CVE-2025-22866
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22872
https://www.cve.org/CVERecord?id=CVE-2025-22872
Référence CVE CVE-2025-3360
https://www.cve.org/CVERecord?id=CVE-2025-3360
Référence CVE CVE-2025-4373
https://www.cve.org/CVERecord?id=CVE-2025-4373
Référence CVE CVE-2025-4802
https://www.cve.org/CVERecord?id=CVE-2025-4802
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Gestion détaillée du document
le 30 octobre 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0896Multiples vulnérabilités dans les produits IBMord?id=CVE-2025-31651
Référence CVE CVE-2025-4565
https://www.cve.org/CVERecord?id=CVE-2025-4565
Référence CVE CVE-2025-46392
https://www.cve.org/CVERecord?id=CVE-2025-46392
Référence CVE CVE-2025-46548
https://www.cve.org/CVERecord?id=CVE-2025-46548
Référence CVE CVE-2025-46653
https://www.cve.org/CVERecord?id=CVE-2025-46653
Référence CVE CVE-2025-47273
https://www.cve.org/CVERecord?id=CVE-2025-47273
Référence CVE CVE-2025-47278
https://www.cve.org/CVERecord?id=CVE-2025-47278
Référence CVE CVE-2025-48387
https://www.cve.org/CVERecord?id=CVE-2025-48387
Référence CVE CVE-2025-48924
https://www.cve.org/CVERecord?id=CVE-2025-48924
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-48988
https://www.cve.org/CVERecord?id=CVE-2025-48988
Référence CVE CVE-2025-48989
https://www.cve.org/CVERecord?id=CVE-2025-48989
Référence CVE CVE-2025-48997
https://www.cve.org/CVERecord?id=CVE-2025-48997
Référence CVE CVE-2025-49005
https://www.cve.org/CVERecord?id=CVE-2025-49005
Référence CVE CVE-2025-49125
https://www.cve.org/CVERecord?id=CVE-2025-49125
Référence CVE CVE-2025-49826
https://www.cve.org/CVERecord?id=CVE-2025-49826
Référence CVE CVE-2025-50059
https://www.cve.org/CVERecord?id=CVE-2025-50059
Référence CVE CVE-2025-50106
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0808Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0760Multiples vulnérabilités dans les produits IBMRecord?id=CVE-2025-4330
Référence CVE CVE-2025-4435
https://www.cve.org/CVERecord?id=CVE-2025-4435
Référence CVE CVE-2025-4517
https://www.cve.org/CVERecord?id=CVE-2025-4517
Référence CVE CVE-2025-46762
https://www.cve.org/CVERecord?id=CVE-2025-46762
Référence CVE CVE-2025-47273
https://www.cve.org/CVERecord?id=CVE-2025-47273
Référence CVE CVE-2025-47287
https://www.cve.org/CVERecord?id=CVE-2025-47287
Référence CVE CVE-2025-48050
https://www.cve.org/CVERecord?id=CVE-2025-48050
Référence CVE CVE-2025-48068
https://www.cve.org/CVERecord?id=CVE-2025-48068
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-50181
https://www.cve.org/CVERecord?id=CVE-2025-50181
Référence CVE CVE-2025-50182
https://www.cve.org/CVERecord?id=CVE-2025-50182
Référence CVE CVE-2025-52999
https://www.cve.org/CVERecord?id=CVE-2025-52999
Référence CVE CVE-2025-53547
https://www.cve.org/CVERecord?id=CVE-2025-53547
Référence CVE CVE-2025-5702
https://www.cve.org/CVERecord?id=CVE-2025-5702
Référence CVE CVE-2025-6442
https://www.cve.org/CVERecord?id=CVE-2025-6442
Référence CVE CVE-2025-7783
https://www.cve.org/CVERecord?id=CVE-2025-7783
Gestion détaillée du document
le 05 septembre 2025
Version initiale
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0746Multiples vulnérabilités dans les produits IBMcord?id=CVE-2025-4373
Référence CVE CVE-2025-4447
https://www.cve.org/CVERecord?id=CVE-2025-4447
Référence CVE CVE-2025-46835
https://www.cve.org/CVERecord?id=CVE-2025-46835
Référence CVE CVE-2025-47273
https://www.cve.org/CVERecord?id=CVE-2025-47273
Référence CVE CVE-2025-47935
https://www.cve.org/CVERecord?id=CVE-2025-47935
Référence CVE CVE-2025-47944
https://www.cve.org/CVERecord?id=CVE-2025-47944
Référence CVE CVE-2025-48060
https://www.cve.org/CVERecord?id=CVE-2025-48060
Référence CVE CVE-2025-48384
https://www.cve.org/CVERecord?id=CVE-2025-48384
Référence CVE CVE-2025-48385
https://www.cve.org/CVERecord?id=CVE-2025-48385
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-48997
https://www.cve.org/CVERecord?id=CVE-2025-48997
Référence CVE CVE-2025-49794
https://www.cve.org/CVERecord?id=CVE-2025-49794
Référence CVE CVE-2025-49796
https://www.cve.org/CVERecord?id=CVE-2025-49796
Référence CVE CVE-2025-50059
https://www.cve.org/CVERecord?id=CVE-2025-50059
Référence CVE CVE-2025-50106
https://www.cve.org/CVERecord?id=CVE-2025-50106
Référence CVE CVE-2025-52434
https://www.cve.org/CVERecord?id=CVE-2025-52434
Référence CVE CVE-2025-52520
https://www.cve.org/CVERecord?id=CVE-2025-52520
Référence CVE CVE-2025-53506
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0727Multiples vulnérabilités dans les produits ESETDe multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0724Multiples vulnérabilités dans les produits IBMd?id=CVE-2025-27789
Référence CVE CVE-2025-30359
https://www.cve.org/CVERecord?id=CVE-2025-30359
Référence CVE CVE-2025-30360
https://www.cve.org/CVERecord?id=CVE-2025-30360
Référence CVE CVE-2025-32996
https://www.cve.org/CVERecord?id=CVE-2025-32996
Référence CVE CVE-2025-32997
https://www.cve.org/CVERecord?id=CVE-2025-32997
Référence CVE CVE-2025-33120
https://www.cve.org/CVERecord?id=CVE-2025-33120
Référence CVE CVE-2025-36042
https://www.cve.org/CVERecord?id=CVE-2025-36042
Référence CVE CVE-2025-47273
https://www.cve.org/CVERecord?id=CVE-2025-47273
Référence CVE CVE-2025-48050
https://www.cve.org/CVERecord?id=CVE-2025-48050
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-50181
https://www.cve.org/CVERecord?id=CVE-2025-50181
Référence CVE CVE-2025-50182
https://www.cve.org/CVERecord?id=CVE-2025-50182
Référence CVE CVE-2025-5889
https://www.cve.org/CVERecord?id=CVE-2025-5889
Référence CVE CVE-2025-6545
https://www.cve.org/CVERecord?id=CVE-2025-6545
Référence CVE CVE-2025-6547
https://www.cve.org/CVERecord?id=CVE-2025-6547
Référence CVE CVE-2025-7339
https://www.cve.org/CVERecord?id=CVE-2025-7339
Référence CVE CVE-2025-7783
https://www.cve.org/CVERecord?id=CVE-2025-7783
Gestion détaillée du document
le 22 août 2025
Version initiale
Alertes
A
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0701Vulnérabilité dans IBM WebSphereUne vulnérabilité a été découverte dans IBM WebSphere. Elle permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0667Multiples vulnérabilités dans Juniper Secure AnalyticsDe multiples vulnérabilités ont été découvertes dans Juniper Secure Analytics. Elle permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0622Multiples vulnérabilités dans les produits VMwareERecord?id=CVE-2025-46701
Référence CVE CVE-2025-46727
https://www.cve.org/CVERecord?id=CVE-2025-46727
Référence CVE CVE-2025-4673
https://www.cve.org/CVERecord?id=CVE-2025-4673
Référence CVE CVE-2025-47290
https://www.cve.org/CVERecord?id=CVE-2025-47290
Référence CVE CVE-2025-48060
https://www.cve.org/CVERecord?id=CVE-2025-48060
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-4877
https://www.cve.org/CVERecord?id=CVE-2025-4877
Référence CVE CVE-2025-4878
https://www.cve.org/CVERecord?id=CVE-2025-4878
Référence CVE CVE-2025-48924
https://www.cve.org/CVERecord?id=CVE-2025-48924
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-48988
https://www.cve.org/CVERecord?id=CVE-2025-48988
Référence CVE CVE-2025-49014
https://www.cve.org/CVERecord?id=CVE-2025-49014
Référence CVE CVE-2025-49124
https://www.cve.org/CVERecord?id=CVE-2025-49124
Référence CVE CVE-2025-49125
https://www.cve.org/CVERecord?id=CVE-2025-49125
Référence CVE CVE-2025-49146
https://www.cve.org/CVERecord?id=CVE-2025-49146
Référence CVE CVE-2025-4949
https://www.cve.org/CVERecord?id=CVE-2025-4949
Référence CVE CVE-2025-50059
https://www.cve.org/CVERecord?id=CVE-2025-50059
Référence CVE CVE-2025-50106
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0608Multiples vulnérabilités dans les produits IBMecord?id=CVE-2025-21587
Référence CVE CVE-2025-22869
https://www.cve.org/CVERecord?id=CVE-2025-22869
Référence CVE CVE-2025-2900
https://www.cve.org/CVERecord?id=CVE-2025-2900
Référence CVE CVE-2025-30698
https://www.cve.org/CVERecord?id=CVE-2025-30698
Référence CVE CVE-2025-32414
https://www.cve.org/CVERecord?id=CVE-2025-32414
Référence CVE CVE-2025-36038
https://www.cve.org/CVERecord?id=CVE-2025-36038
Référence CVE CVE-2025-36097
https://www.cve.org/CVERecord?id=CVE-2025-36097
Référence CVE CVE-2025-4447
https://www.cve.org/CVERecord?id=CVE-2025-4447
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976
Référence CVE CVE-2025-48988
https://www.cve.org/CVERecord?id=CVE-2025-48988
Référence CVE CVE-2025-49125
https://www.cve.org/CVERecord?id=CVE-2025-49125
Référence CVE CVE-2025-5283
https://www.cve.org/CVERecord?id=CVE-2025-5283
Gestion détaillée du document
le 18 juillet 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des s
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0516Multiples vulnérabilités dans Apache TomcatDe multiples vulnérabilités ont été découvertes dans Apache Tomcat. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2025-000044複数のApache製品におけるサービス運用妨害(DoS)の脆弱性The Apache Software Foundationが提供する複数の製品には、次の脆弱性が存在します。 制限または調整なしのリソースの割り当て(CWE-770)- CVE-2025-48976、CVE-2025-48988
この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方がIPAに報告し、JPCERT/CCが開発者との調整を行いました。 報告者:NTTデータグループ TERASOLUNA Framework セキュリティチーム
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-007524Hitachi Command Suite製品における脆弱性Hitachi Command Suite製品に脆弱性(CVE-2025-48976)が存在します。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-002030Cosminexusにおける複数の脆弱性Cosminexus Component Containerに以下の脆弱性が存在します。 CVE-2025-48988, CVE-2025-48976 影響を受けるバージョンを下記に示しますので,対策版の適用をお願いします。 なお,Servlet仕様のファイルアップロード機能を使用していない場合は発生しません。 また本問題は,Cosminexus Component Containerを構成製品とする,日立製品にも該当します。 Cosminexus製品で影響を受けるバージョンを下記に示します。Cosminexus製品に含まれるCosminexus Component Containerのバージョン,及びCosminexus製品の対策バージョンについては,サポートサービス窓口へご相談願います。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0034Kwetsbaarheden verholpen in Atlassian productenMultiple denial-of-service vulnerabilities have been identified in Oracle Application Testing Suite, Oracle Agile PLM, Apache Commons FileUpload, and HPE IceWall Identity Manager, with CVSS scores of 7.5 for some products.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0027Kwetsbaarheden verholpen in Oracle Fusion MiddlewareMultiple denial-of-service vulnerabilities have been identified in Oracle Application Testing Suite, Oracle Agile PLM, Apache Commons FileUpload, and HPE IceWall Identity Manager, with CVSS scores of 7.5 for some products.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0025Kwetsbaarheden verholpen in Oracle Financial ServicesMultiple denial-of-service vulnerabilities have been identified in Oracle Application Testing Suite, Oracle Agile PLM, Apache Commons FileUpload, and HPE IceWall Identity Manager, with CVSS scores of 7.5 for some products.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0022Kwetsbaarheden verholpen in Oracle Communications productenMultiple denial-of-service vulnerabilities have been identified in Oracle Application Testing Suite, Oracle Agile PLM, Apache Commons FileUpload, and HPE IceWall Identity Manager, with CVSS scores of 7.5 for some products.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0395Kwetsbaarheden verholpen in SAP SoftwareMultiple denial of service (DoS) vulnerabilities have been identified in Oracle Application Testing Suite, Apache Commons FileUpload, and SAP Business Objects, affecting various versions and allowing potential exploitation by attackers.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0336Kwetsbaarheden verholpen in Oracle HyperionMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0335Kwetsbaarheden verholpen in Oracle AnalyticsMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0334Kwetsbaarheden verholpen in Oracle Fusion MiddlewareMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload could lead to denial of service (DoS) attacks, with specific versions identified as vulnerable.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0333Kwetsbaarheden verholpen in Oracle Financial ServicesMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0332Kwetsbaarheden verholpen in Oracle Enterprise ManagerMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0330Kwetsbaarheden verholpen in Oracle Communications productenMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0329Kwetsbaarheden verholpen in Oracle CommerceMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0328Kwetsbaarheden verholpen in Oracle Database productenMultiple vulnerabilities affecting Oracle Application Testing Suite and Apache Commons FileUpload, including DoS risks due to insufficient multipart header limits, have been identified, with CVSS scores reaching 7.5.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0274Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- (Remote) code execution (root/admin rechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Verhogen van rechten
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0195Kwetsbaarheden verholpen in Apache TomcatDe kwetsbaarheden omvatten een denial-of-service door onvoldoende limieten op multipart headers, een gebrek aan resource allocatie zonder limieten, een onbetrouwbaar zoekpad in de Windows installer, en een kritieke authenticatie omzeiling door onjuiste padverwerking. Aanvallers kunnen deze kwetsbaarheden misbruiken door speciaal samengestelde verzoeken te sturen, wat kan leiden tot ongeoorloofde toegang tot gevoelige bestanden en geheugenuitputting, met als gevolg een verstoring van de service.
Official advisory ↗