NetWitness Platform: 12.5.2 Vulnerabilities
Advisory Type
Security
Advisory Content
This advisory addresses vulnerabilities that have been identified within the NetWitness Platform.
CVE Identifier
NW-2026:01
Severity Rating
CVSS v3 Base Score: See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
Affected Products
NetWitness Platform versions prior to 12.5.2.0
Summary
Multiple components within the NetWitness Platform require a security update to address various vulnerabilities.
MAJOR:
CVE-2025-32462, CVE-2025-38380, CVE-2025-38052, CVE-2025-38350, CVE-2025-7425, CVE-2025-38352, CVE-2025-58060, CVE-2025-8941, CVE-2025-37890, CVE-2025-6020, CVE-2025-1691, CVE-2025-1756, CVE-2025-59375, CVE-2025-11561, CVE-2025-40778, CVE-2025-14847, CVE-2025-3083, CVE-2025-66293, CVE-2025-64720, CVE-2025-65018, CVE-2025-3085, CVE-2025-53066, CVE-2023-0286, CVE-2025-5914, CVE-2025-6965, CVE-2024-55549, CVE-2025-1094, CVE-2025-50059, CVE-2025-50106, CVE-2025-30749, CVE-2025-66418, CVE-2025-66471, CVE-2026-21441
MODERATE:
CVE-2024-47554, CVE-2020-11023, CVE-2025-22020, CVE-2025-21727, CVE-2025-37914, CVE-2022-49977, CVE-2021-47670, CVE-2025-38079, CVE-2025-38085, CVE-2025-38250, CVE-2022-50020, CVE-2025-38159, CVE-2025-26465, CVE-2025-38211, CVE-2025-38332, CVE-2025-38464, CVE-2025-38477, CVE-2023-53125, CVE-2025-38392, CVE-2025-38449, CVE-2025-22058, CVE-2025-38200, CVE-2025-21905, CVE-2025-21919, CVE-2022-50087, CVE-2025-22026, CVE-2025-37797, CVE-2025-38718, CVE-2025-8194, CVE-2024-50154, CVE-2025-38086, CVE-2022-50386, CVE-2023-53297, CVE-2023-53386, CVE-2025-39817, CVE-2025-39841, CVE-2025-39849, CVE-2025-38556, CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2025-22097, CVE-2025-32415, CVE-2022-49985, CVE-2022-50228, CVE-2023-53305, CVE-2025-21759, CVE-2025-21928, CVE-2023-53373, CVE-2025-39757, CVE-2025-38527, CVE-2025-39730, CVE-2025-1692, CVE-2025-8058, CVE-2022-50367, CVE-2023-53178, CVE-2025-40300, CVE-2024-47081, CVE-2025-39718, CVE-2025-39697, CVE-2025-39971, CVE-2023-53257, CVE-2023-53226, CVE-2025-39864, CVE-2025-61984, CVE-2025-61985, CVE-2025-9086, CVE-2025-11083, CVE-2023-53401, CVE-2023-53539, CVE-2022-50543, CVE-2023-53513, CVE-2025-38724, CVE-2025-39825, CVE-2025-39883, CVE-2025-39955, CVE-2025-38461, CVE-2025-38498, CVE-2025-58364, CVE-2025-6707, CVE-2025-3084, CVE-2023-40403, CVE-2020-13790, CVE-2025-32414, CVE-2025-39898, CVE-2025-5318, CVE-2025-39751, CVE-2025-53906, CVE-2025-8291, CVE-2025-12084, CVE-2025-53057, CVE-2024-34397, CVE-2024-52533, CVE-2025-4373, CVE-2023-31484, CVE-2024-12243, CVE-2020-16156, CVE-2025-5372, CVE-2025-53905, CVE-2023-49083, CVE-2025-47273, CVE-2019-17543, CVE-2025-40909, CVE-2024-50301, CVE-2022-48919, CVE-2022-49136, CVE-2022-49111, CVE-2025-30761, CVE-2025-30754, CVE-2025-13601, CVE-2025-61915, CVE-2025-58436, CVE-2026-0865, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2025-38403, CVE-2025-40170, CVE-2025-40135, CVE-2025-40158, CVE-2025-40269, CVE-2022-50673, CVE-2025-68349, CVE-2026-22998
MINOR:
CVE-2025-1693, CVE-2025-3082
Details
The embedded components are updated for the following vulnerabilities:
- CVE-2024-47554
https://www.cve.org/CVERecord?id=CVE-2024-47554 - CVE-2020-11023
https://access.redhat.com/errata/RHSA-2020:4211 - CVE-2025-32462
https://errata.almalinux.org/8/ALSA-2025-10110.html - CVE-2025-22020
https://errata.almalinux.org/8/ALSA-2025-12752.html - CVE-2025-21727
https://errata.almalinux.org/8/ALSA-2025-13589.html - CVE-2025-37914
https://errata.almalinux.org/8/ALSA-2025-13960.html - CVE-2022-49977
https://errata.almalinux.org/8/ALSA-2025-11850.html - CVE-2025-37890, CVE-2025-21928
https://errata.almalinux.org/8/ALSA-2025-12752.html - CVE-2021-47670
https://errata.almalinux.org/8/ALSA-2025-13589.html - CVE-2025-38380
https://errata.almalinux.org/8/ALSA-2025-13960.html - CVE-2025-38079
https://errata.almalinux.org/8/ALSA-2025-12752.html - CVE-2025-38085
https://errata.almalinux.org/8/ALSA-2025-13589.html - CVE-2025-38250
https://errata.almalinux.org/8/ALSA-2025-13960.html - CVE-2022-50020
https://errata.almalinux.org/8/ALSA-2025-12752.html - CVE-2025-38159
https://errata.almalinux.org/8/ALSA-2025-13589.html - CVE-2025-38052
https://errata.almalinux.org/8/ALSA-2025-12752.html - CVE-2025-38352
https://errata.almalinux.org/8/ALSA-2025-15471.html - CVE-2025-26465
https://errata.almalinux.org/8/ALSA-2025-16823.html - CVE-2025-58060
https://errata.almalinux.org/8/ALSA-2025-15702.html - CVE-2025-38461, CVE-2025-38498, CVE-2025-38556
https://errata.almalinux.org/8/ALSA-2025-16372.html - CVE-2025-38211, CVE-2025-38332, CVE-2025-38464, CVE-2025-38477
https://errata.almalinux.org/8/ALSA-2025-15008.html - CVE-2023-53125, CVE-2025-38350, CVE-2025-38392, CVE-2025-38449
https://errata.almalinux.org/8/ALSA-2025-15785.html - CVE-2025-22058, CVE-2025-38200
https://errata.almalinux.org/8/ALSA-2025-14438.html - CVE-2025-7425
https://errata.almalinux.org/8/ALSA-2025-12450.html - CVE-2025-21905, CVE-2025-21919
https://errata.almalinux.org/8/ALSA-2025-11850.html - CVE-2022-50087, CVE-2025-22026, CVE-2025-37797, CVE-2025-38718
https://errata.almalinux.org/8/ALSA-2025-16919.html - CVE-2025-38352, CVE-2022-49985
https://errata.almalinux.org/8/ALSA-2025-15471.html - CVE-2025-8194
https://www.cve.org/CVERecord?id=CVE-2025-8194 - CVE-2025-22097
https://errata.almalinux.org/8/ALSA-2025-13960.html - CVE-2024-50154, CVE-2025-38086
https://errata.almalinux.org/8/ALSA-2025-11455.html - CVE-2022-50386, CVE-2023-53297, CVE-2023-53386, CVE-2025-39817, CVE-2025-39841, CVE-2025-39849
https://errata.almalinux.org/8/ALSA-2025-19102.html - CVE-2025-32988, CVE-2025-32990, CVE-2025-6395
https://errata.almalinux.org/8/ALSA-2025-17415.html - CVE-2025-32415
https://errata.almalinux.org/8/ALSA-2025-13203.html - CVE-2025-8941
https://www.cve.org/CVERecord?id=CVE-2025-8941 - CVE-2022-50228, CVE-2023-53305
https://errata.almalinux.org/8/ALSA-2025-17797.html - CVE-2025-21759
https://errata.almalinux.org/8/ALSA-2025-13589.html - CVE-2023-53373, CVE-2025-39757
https://errata.almalinux.org/8/ALSA-2025-18297.html - CVE-2025-38527, CVE-2025-39730
https://errata.almalinux.org/8/ALSA-2025-17397.html - CVE-2025-6020
https://www.cve.org/CVERecord?id=CVE-2025-6020 - CVE-2025-1691
https://www.cve.org/CVERecord?id=CVE-2025-1691 - CVE-2025-1692
https://www.cve.org/CVERecord?id=CVE-2025-1692 - CVE-2025-1693
https://www.cve.org/CVERecord?id=CVE-2025-1693 - CVE-2025-1756
https://www.cve.org/CVERecord?id=CVE-2025-1756 - CVE-2025-8058
https://www.cve.org/CVERecord?id=CVE-2025-8058 - CVE-2022-50367, CVE-2023-53178, CVE-2025-40300
https://errata.almalinux.org/8/ALSA-2025-19931.html - CVE-2025-59375
https://www.cve.org/CVERecord?id=CVE-2025-59375 - CVE-2024-47081
https://www.cve.org/CVERecord?id=CVE-2024-47081 - CVE-2025-11561
https://www.cve.org/CVERecord?id=CVE-2025-11561 - CVE-2025-39718
https://errata.almalinux.org/8/ALSA-2025-21398.html - CVE-2025-39697, CVE-2025-39971
https://errata.almalinux.org/8/ALSA-2025-21917.html - CVE-2023-53257, CVE-2023-53226, CVE-2025-39864
https://errata.almalinux.org/8/ALSA-2025-19447.html - CVE-2025-40778
https://www.cve.org/CVERecord?id=CVE-2025-40778 - CVE-2025-61984
https://www.cve.org/CVERecord?id=CVE-2025-61984 - CVE-2025-61985
https://www.cve.org/CVERecord?id=CVE-2025-61985 - CVE-2025-9086
https://www.cve.org/CVERecord?id=CVE-2025-9086 - CVE-2025-11083
https://www.cve.org/CVERecord?id=CVE-2025-11083 - CVE-2022-50543, CVE-2023-53401, CVE-2023-53539
https://errata.almalinux.org/8/ALSA-2025-22801.html - CVE-2025-58364
https://www.cve.org/CVERecord?id=CVE-2025-58364 - CVE-2023-53513, CVE-2025-38724, CVE-2025-39825, CVE-2025-39883, CVE-2025-39955, CVE-2025-39898
https://errata.almalinux.org/8/ALSA-2025-22388.html - CVE-2025-14847
https://www.cve.org/CVERecord?id=CVE-2025-14847 - CVE-2025-3082
https://www.cve.org/CVERecord?id=CVE-2025-3082 - CVE-2025-3083
https://www.cve.org/CVERecord?id=CVE-2025-3083 - CVE-2025-6707
https://www.cve.org/CVERecord?id=CVE-2025-6707 - CVE-2025-3084
https://www.cve.org/CVERecord?id=CVE-2025-3084 - CVE-2023-40403
https://nvd.nist.gov/vuln/detail/CVE-2023-40403 - CVE-2020-13790
https://nvd.nist.gov/vuln/detail/CVE-2020-13790 - CVE-2025-32414
https://www.cve.org/CVERecord?id=CVE-2025-32414 - CVE-2025-66293
https://www.cve.org/CVERecord?id=CVE-2025-66293 - CVE-2025-64720
https://nvd.nist.gov/vuln/detail/CVE-2025-64720 - CVE-2025-65018
https://www.cve.org/CVERecord?id=CVE-2025-65018 - CVE-2025-3085
https://www.cve.org/CVERecord?id=CVE-2025-3085 - CVE-2025-5318
https://www.cve.org/CVERecord?id=CVE-2025-5318 - CVE-2025-39751
https://errata.almalinux.org/8/ALSA-2025-18297.html - CVE-2025-5372
https://www.cve.org/CVERecord?id=CVE-2025-5372 - CVE-2025-8291
https://www.cve.org/CVERecord?id=CVE-2025-8291 - CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084 - CVE-2025-53057
https://www.cve.org/CVERecord?id=CVE-2025-53057 - CVE-2024-34397
https://www.cve.org/CVERecord?id=CVE-2024-34397 - CVE-2024-52533
https://www.cve.org/CVERecord?id=CVE-2024-52533 - CVE-2025-4373
https://www.cve.org/CVERecord?id=CVE-2025-4373
- CVE-2025-47273
https://www.cve.org/CVERecord?id=CVE-2025-47273
- CVE-2023-31484
https://www.cve.org/CVERecord?id=CVE-2023-31484
- CVE-2024-12243
https://www.cve.org/CVERecord?id=CVE-2024-12243
- CVE-2020-16156
https://www.cve.org/CVERecord?id=CVE-2020-16156
- CVE-2025-53066
https://www.cve.org/CVERecord?id=CVE-2025-53066
- CVE-2023-0286
https://www.cve.org/CVERecord?id=CVE-2023-0286
- CVE-2025-53906, CVE-2025-53905
https://errata.almalinux.org/8/ALSA-2025-17715.html
- CVE-2023-49083
https://www.cve.org/CVERecord?id=CVE-2023-49083
- CVE-2019-17543
https://www.cve.org/CVERecord?id=CVE-2019-17543
- CVE-2025-40909
https://www.cve.org/CVERecord?id=CVE-2025-40909
- CVE-2024-50301, CVE-2022-48919
https://errata.almalinux.org/8/ALSA-2025-9580.html
- CVE-2022-49136, CVE-2022-49111
https://errata.almalinux.org/8/ALSA-2025-10669.html
- CVE-2025-5914
https://errata.almalinux.org/8/ALSA-2025-14135.html
- CVE-2025-6965
https://www.cve.org/CVERecord?id=CVE-2025-6965
- CVE-2024-55549
https://www.cve.org/CVERecord?id=CVE-2024-55549
- CVE-2025-1094
https://www.cve.org/CVERecord?id=CVE-2025-1094
- CVE-2025-50059
https://www.cve.org/CVERecord?id=CVE-2025-50059
- CVE-2025-50106
https://www.cve.org/CVERecord?id=CVE-2025-50106
- CVE-2025-30749
https://www.cve.org/CVERecord?id=CVE-2025-30749
- CVE-2025-30761
https://www.cve.org/CVERecord?id=CVE-2025-30761
- CVE-2025-30754
https://www.cve.org/CVERecord?id=CVE-2025-30754
- CVE-2025-66418, CVE-2025-66471, CVE-2026-21441
https://errata.almalinux.org/8/ALSA-2026-1254.html
- CVE-2025-13601
https://errata.almalinux.org/8/ALSA-2026-0991.html
- CVE-2025-61915
https://errata.almalinux.org/8/ALSA-2026-0596.html
- CVE-2025-58436
https://errata.almalinux.org/8/ALSA-2026-0596.html
- CVE-2026-0865, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299
https://errata.almalinux.org/8/ALSA-2026-2128.html
- CVE-2025-38403, CVE-2025-40170, CVE-2025-40135, CVE-2025-40158, CVE-2025-40269, CVE-2022-50673, CVE-2025-68349, CVE-2026-22998
https://errata.almalinux.org/8/ALSA-2026-2264.html
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at https://nvd.nist.gov/home#. To search for a particular CVE, use the database’s search utility at https://nvd.nist.gov/search
Recommendation
The following NetWitness Platform release contains resolutions to these vulnerabilities: NetWitness Platform 12.5.2.0.
NetWitness® recommends all customers upgrade at the earliest opportunity.
For additional documentation, downloads and more, visit the NetWitness Platform page on NetWitness Community.
Severity Rating
For an explanation of Severity Ratings, refer to the Vulnerability Disclosure Policy. NetWitness® recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.
EOPS Policy
NetWitness® has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.
Legal Information
Read and use the information in this NetWitness Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact NetWitness Customer Support. NetWitness Security LLC and its affiliates distribute NetWitness Security Advisories in order to bring to the attention of users of the affected NetWitness products, important security information.
NetWitness recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. NetWitness disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement.
In no event shall NetWitness, its affiliates or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if NetWitness, its affiliates or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.