CVE-2025-47222

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.
Configurations

Configuration 1 (hide)

cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*

History

17 Dec 2025, 20:15

Type Values Removed Values Added
Summary (en) A class name enumeration issue was found in Keyfactor SignServer versions prior to 7.3.2. (en) A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.
References
  • () https://support.keyfactor.com/hc/en-us/articles/37639174814235-SignServer-CVE-2025-47222-Class-name-enumeration -

09 Dec 2025, 17:15

Type Values Removed Values Added
Summary (en) Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 3 of 3. (en) A class name enumeration issue was found in Keyfactor SignServer versions prior to 7.3.2.

24 Nov 2025, 12:27

Type Values Removed Values Added
References () https://docs.keyfactor.com/signserver/latest/signserver-7-3-release-notes - () https://docs.keyfactor.com/signserver/latest/signserver-7-3-release-notes - Release Notes
References () https://support.keyfactor.com - () https://support.keyfactor.com - Product
CPE cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*
First Time Keyfactor signserver
Keyfactor

14 Nov 2025, 17:16

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Nov 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 21:15

Updated : 2025-12-17 20:15


NVD link : CVE-2025-47222

Mitre link : CVE-2025-47222

CVE.ORG link : CVE-2025-47222


JSON object : View

Products Affected

keyfactor

  • signserver
CWE
CWE-284

Improper Access Control