BAE Systems maintains a narrow portfolio centered on specialized geospatial and imagery-analysis software such as SOCET GXP, products deployed in defense and intelligence workflows where access control and data protection are mission-critical. The recurring vulnerability pattern reflects the web-service and file-handling architecture of these tools, centering on improper access control, cross-site scripting, CSRF, path traversal, and sensitive-information exposure—a profile typical of enterprise analysis platforms where authentication boundaries and input sanitization are complex. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baesystems over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54964HIGH An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is c | Oct 23, 2025 | 8.4 | 27 | NO | NO |
CVE-2025-54968HIGH An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jo | Oct 27, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-54970MEDIUM An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local use | Oct 27, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-54963MEDIUM An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafted job request that grants read access | Oct 23, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-54965MEDIUM An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID parameter before using it in the job status page | Oct 27, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-54969MEDIUM An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into cl | Oct 27, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-54967MEDIUM An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able to social engineer a SOCET GXP user into o | Oct 27, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-54966MEDIUM An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive information in certain situations, including local | Oct 23, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baesystems.
Media articles that mention a CVE ID that affects a product developed by Baesystems — matched by CVE ID, not by vendor name.