Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information.
History

Fri, 21 Nov 2025 21:45:00 +0000

Type Values Removed Values Added
Description Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information.
Title Black Duck SCA Project Privilege Escalation
First Time appeared Black Duck
Black Duck black Duck Sca
Weaknesses CWE-266
CPEs cpe:2.3:a:black_duck:black_duck_sca:*:*:*:*:*:*:*:*
Vendors & Products Black Duck
Black Duck black Duck Sca
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: BlackDuck

Published:

Updated: 2025-11-21T21:30:53.934Z

Reserved: 2025-01-15T18:37:28.166Z

Link: CVE-2025-0504

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.