CVE-2025-10555

8.7

Dassault Systèmes · DELMIA Service Process Engineer

A stored Cross-site Scripting (XSS) vulnerability in DELMIA Service Process Engineer allows authenticated attackers to execute arbitrary script code within a user's browser session.

Executive summary

A stored Cross-site Scripting vulnerability in Dassault Systèmes DELMIA Service Process Engineer poses a risk of unauthorized code execution within user sessions.

Vulnerability

This is a stored Cross-site Scripting (CWE-79) vulnerability located within the Service Items Management component. The vulnerability requires the attacker to have low-level authenticated access to the system to trigger the payload.

Business impact

The exploitation of this vulnerability allows an attacker to execute arbitrary scripts in the context of an authenticated user session. This can lead to the theft of session tokens, unauthorized actions performed on behalf of the user, or the exfiltration of sensitive information, potentially impacting the integrity and confidentiality of the engineering environment. Given the CVSS score of 8.7, this is considered a high-severity risk that demands immediate attention to prevent unauthorized session manipulation.

Remediation

Immediate Action: Review the official Dassault Systèmes security advisory at the provided reference link and apply all relevant security updates or configuration changes recommended by the vendor.

Proactive Monitoring: Monitor application logs for suspicious input patterns within the Service Items Management module, particularly those containing script tags or encoded payloads.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured to detect and block common XSS injection patterns targeting the application endpoints.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing the affected versions of DELMIA Service Process Engineer should prioritize the implementation of vendor-supplied mitigations to neutralize this stored XSS risk. Failure to address this vulnerability could allow malicious actors to compromise user sessions, leading to unauthorized data access or system manipulation. Administrators should verify their current deployment version against the affected range and apply updates as soon as they become available.

More Dassault Systèmes CVEs

Sources