Home

Description

Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This issue affects Command Centre Server: 9.30.1874 (MR1), 9.20.2337 (MR3), 9.10.3194 (MR6).

PUBLISHED Reserved 2025-06-17 | Published 2025-10-23 | Updated 2025-10-23 | Assigner Gallagher




MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-359 Exposure of Private Personal Information to an Unauthorized Actor

Product status

Default status
unaffected

9.30.1874 (MR1) (custom)
affected

9.20.2337 (MR3)
affected

9.10.3194 (MR6)
affected

References

security.gallagher.com/...Security-Advisories/CVE-2025-35981

cve.org (CVE-2025-35981)

nvd.nist.gov (CVE-2025-35981)

Download JSON