Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.
The problem results from Axxon One software's dependency on an outdated PostgreSQL component in the v10.x branch (CWE-1395 — Dependency on Vulnerable Third-Party Component). This version of PostgreSQL contains numerous known vulnerabilities that were fixed only in PostgreSQL 17.4. The database backend is accessible over the network, allowing a remote attacker to directly exploit these vulnerabilities without requiring credentials or user interaction.
An attacker can obtain privilege escalation, execute arbitrary code (RCE) on the target system, or cause a denial of service (DoS). The vulnerability affects the confidentiality, integrity, and availability of the system.
AxxonSoft Axxon One must be updated to a version containing PostgreSQL 17.4 or newer. Detailed information about available patches should be checked in the vendor references at: https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories. Until the update is applied, it is recommended to restrict network access to the PostgreSQL port only to trusted hosts using a firewall.
AxxonSoft Axxon One (C-Werk) version 2.0.8 and earlier, running on Windows and Linux systems with embedded PostgreSQL v10.x backend.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAxxonsoft Axxon One
APPAxxonsoft≤ 2.0.8Linux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit