CVE-2025-46574: ZTE GoldenDB Database product has an input validation vulnerability
Published Apr 27, 2025
·Updated
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
Affected Software
4 affected components
ZTE GoldenDB
ZTE Zxcloud Goldendb>=6.1.03<6.1.03.11
ZTE Zxcloud Goldendb=7.2.01.01
ZTE Zxcloud Goldendb=7.2.01.01
Remediation
Information
6.1.03.11,7.2.01.01P1,Lite7.2.01.01P1
Event History
Apr 27, 2025
CVE Published
via MITRE·01:07 AM
Data Sourced
via MITRE·01:07 AM
RemedyDescriptionSeverityWeakness
Oct 7, 57345
Event
via FIRST·11:21 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-46574?
CVE-2025-46574 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-46574?
To fix CVE-2025-46574, update the GoldenDB database to the latest patched version provided by ZTE.
3
What kind of information can be disclosed due to CVE-2025-46574?
CVE-2025-46574 can lead to the disclosure of sensitive system information through error messages.
4
Which product is affected by CVE-2025-46574?
CVE-2025-46574 affects the ZTE GoldenDB database product.
5
Can CVE-2025-46574 be exploited remotely?
Yes, CVE-2025-46574 can be exploited remotely by attackers to obtain sensitive information.