CVE-2025-3113: Perforce Delphix

Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the application’s built-in Connector functionality to access Continuous Compliance’s internal database. This allows the user to explore the internal database schema and export its data, including the properties of Connecters and Rule Sets.

Affected products

  • Perforce Delphix: before 2025.2.0.1 (fixed in 2025.2.0.1)

Published 2025-04-17. Last modified 2026-06-17.