CVE-2025-47222

A

class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.

Configurations

Configuration 1 (hide)

cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*

History

17 Dec 2025, 20:15

Type Values Removed Values Added
Summary (en) Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 3 of 3. (en) A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.
References
  • () https://support.keyfactor.com/hc/en-us/articles/37639174814235-SignServer-CVE-2025-47222-Class-name-enumeration -

24 Nov 2025, 12:27

Type Values Removed Values Added
First Time Keyfactor signserver
Keyfactor
CPE cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*
References () https://docs.keyfactor.com/signserver/latest/signserver-7-3-release-notes - () https://docs.keyfactor.com/signserver/latest/signserver-7-3-release-notes - Release Notes
References () https://support.keyfactor.com - () https://support.keyfactor.com - Product

14 Nov 2025, 17:16

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Nov 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 21:15

Updated : 2025-12-17 20:15


NVD link : CVE-2025-47222

Mitre link : CVE-2025-47222

CVE.ORG link : CVE-2025-47222


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control