9.1

CVE-2025-6205

Warnung
Medienbericht
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
3dsDelmia Apriso Version >= 2020 < 2025

28.10.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Schwachstelle

Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 55.68% 0.98
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
3DS.Information-Security@3ds.com 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.