CVE Vulnerabilities

CVE-2025-46576

Improper Privilege Management

Published: Apr 27, 2025 | Modified: May 12, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Zxcloud_goldendb Zte 6.1.03.09 (including) 6.1.03.09 (including)
Zxcloud_goldendb Zte 6.1.03.10 (including) 6.1.03.10 (including)
Zxcloud_goldendb Zte 7.2.01.01 (including) 7.2.01.01 (including)

Potential Mitigations

References