CVE-2025-10553

8.7

Dassault Systèmes · DELMIA Factory Resource Manager

A stored XSS vulnerability in DELMIA Factory Resource Manager allows authenticated attackers to execute arbitrary script code within a user's browser session.

Executive summary

A high-severity stored Cross-site Scripting vulnerability in Dassault Systèmes DELMIA Factory Resource Manager exposes users to potential session hijacking and unauthorized actions.

Vulnerability

This is a stored Cross-site Scripting (CWE-79) vulnerability where an authenticated attacker can inject malicious scripts into the application, which then execute in the context of other users' browser sessions.

Business impact

Successful exploitation allows an attacker to execute arbitrary scripts in the victim's browser, potentially leading to session theft, unauthorized data access, or the performance of actions on behalf of the victim. Given the CVSS score of 8.7, this represents a significant risk to organizational data integrity and user account security, particularly if administrative accounts are targeted.

Remediation

Immediate Action: Review the official security advisory at the Dassault Systèmes Trust Center and apply the latest provided security updates or hotfixes for the affected 3DEXPERIENCE releases.

Proactive Monitoring: Monitor web application logs for suspicious input patterns or script-like characters in fields processed by the Factory Resource Management module.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common cross-site scripting injection attempts.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Organizations utilizing the affected versions of DELMIA Factory Resource Manager should prioritize the application of vendor-supplied patches to remediate this vulnerability. Given the potential for session compromise, administrators should also consider auditing current user sessions and enforcing stricter input validation policies for all web-based interfaces.

More Dassault Systèmes CVEs

Sources