CVE-2025-8386EPSS p4.4%
CVE-2025-8386CVE-2025-8386
Description
The vulnerability, if exploited, could allow an authenticated miscreant
(with privilege of "aaConfigTools") to tamper with App Objects' help
files and persist a cross-site scripting (XSS) injection that when
executed by a victim user, can result in horizontal or vertical
escalation of privileges. The vulnerability can only be exploited during
config-time operations within the IDE component of Application Server.
Run-time components and operations are not affected.
Scoring
| CVSS | 6.9 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L |
| EPSS | 0.16% probability of exploitation · percentile 4.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |