Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information. | |
| Title | Black Duck SCA Project Privilege Escalation | |
| First Time appeared |
Black Duck
Black Duck black Duck Sca |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:2.3:a:black_duck:black_duck_sca:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Black Duck
Black Duck black Duck Sca |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: BlackDuck
Published:
Updated: 2025-11-21T21:30:53.934Z
Reserved: 2025-01-15T18:37:28.166Z
Link: CVE-2025-0504
No data.
No data.
No data.