PatchSiren cyber security CVE debrief
CVE-2025-61023 OpenLink CVE debrief
CVE-2025-61023 is a high-severity vulnerability in the st_compare component of openlink virtuoso-opensource v7.2.11. The issue allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. The CVE record was published on 2026-06-23T17:16:39.363Z and last modified on 2026-06-25T19:16:35.080Z. The vulnerability affects openlink virtuoso-opensource v7.2.11, but details about the vendor and product are not available.
- Vendor
- OpenLink
- Product
- virtuoso-opensource
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-25
Who should care
Security teams and administrators responsible for openlink virtuoso-opensource v7.2.11 should be aware of this vulnerability. The vulnerability has a high CVSS score, indicating a significant risk to affected systems. Organizations using this software should review their inventory and apply necessary patches or mitigations.
Technical summary
The vulnerability is located in the st_compare component of openlink virtuoso-opensource v7.2.11. Attackers can exploit this vulnerability by sending crafted SQL statements, which can cause a Denial of Service (DoS). The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a high severity. The weakness associated with this vulnerability is CWE-89.
Defensive priority
High priority should be given to patching or mitigating this vulnerability due to its high CVSS score and potential impact on affected systems.
Recommended defensive actions
- Review inventory to identify affected systems
- Apply patches or updates provided by the vendor
- Implement compensating controls to mitigate the vulnerability
- Monitor systems for suspicious activity
- Consider isolating affected systems until patched
Evidence notes
The CVE record and NVD detail provide information about this vulnerability. The CVE record was published on 2026-06-23T17:16:39.363Z and last modified on 2026-06-25T19:16:35.080Z. The NVD detail provides additional information about the vulnerability, including its CVSS score and vector.
Official resources
-
CVE-2025-61023 CVE record
CVE.org
-
CVE-2025-61023 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
This article is AI-assisted and based on the supplied source corpus.