Internal Database Exposure in Continuous Compliance by Perforce
CVE-2025-3113

9CRITICAL

Key Information:

Vendor

Perforce

Status
Vendor
CVE Published:
17 April 2025

What is CVE-2025-3113?

An authenticated user with adequate privileges in Continuous Compliance can exploit the application’s Connector feature to gain unauthorized access to the internal database. This enables the user to view and export sensitive data, including internal schema properties, which may lead to potential information leaks and compliance issues.

Affected Version(s)

Delphix 0 < 2025.2.0.1

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.