CVE-2025-54969 Details
Description
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service without the user's knowledge.
A client-side request forgery (CSRF) vulnerability has been identified in BAE SOCET GXP versions prior to 4.6.0.2. The issue arises because the SOCET GXP Job Status Service lacks proper CSRF protections. This vulnerability allows an attacker to social engineer a valid user into clicking a malicious link or visiting a harmful website, potentially leading to unauthorized requests being sent to the Job Status Service without the user's awareness. Exploitation of this vulnerability could enable an attacker to manipulate job information, such as purging job data, aborting jobs, or restarting the Job Status Service.
Users are advised to update to SOCET GXP version 4.6.0.2 or later, as this version disables network access for the GXP Job Status Service by default. For those unable to update immediately, the Job Status Service HTTP endpoint can be disabled manually by modifying the 'js-config.xml' file in the SOCET GXP Installation Directory, then restarting the application. Users should exercise caution when clicking links from untrusted sources.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| baesystems socet gxp | < 4.6.0.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 31, 2025 | Initial Analysis | [email protected] |
| Oct 27, 2025 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | New CVE Received | [email protected] |