CVE-2025-11843 - CVE House
Back to Database
Status published High CVE-2025-11843

Therefore™ Online and Therefore™ On-Premises contains an account impersonation issue, which could potentially allow the attacker to access all the stored data

Vulnerability Description

Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API when connecting to the Therefore™ Server. If the malicious user gains this impersonation user access, then it is possible for them to access the documents stored in Therefore™. This impersonation is at application level (Therefore access level), not the operating system level.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11843

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Therefore Corporation GmbH

View all reports →

Affected Software

Therefore Online and Therefore On-Premises
Vulnerable Versions:
0

Timeline

Official Publish: October 31st, 2025
Last Modified: October 31st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)