Server-Side Request Forgery (SSRF) in axios - CVE-2025-27152
Published: March 7, 2025 / Updated: June 13, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Python 3 Module
openSUSE Leap
Event Processing
Software Support app (Android)
Storage Defender - Resiliency Service
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Storage Ceph
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite - Edge Data Collector
IBM Business Automation Manager Open Editions
Robotic Process Automation for Cloud Pak
Business Automation Insights
QRadar Deployment Intelligence App
Telco Unified OSS Console
Maximo Application Suite - IoT Component
IBM Concert Software
Netcool Operations Insight
IBM Decision Optimization for Cloud Pak for Data
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite
Bamboo Server
Jira Software Data Center
IBM Robotic Process Automation
IBM Automation Decision Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM Cloud Pak for Security
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Voice Gateway
watsonx.data
IBM Cloud Pak System
strapi
Cloud Pak for Data
IBM License Metric Tool
Jira Software Server
Event Streams
IBM Security SOAR
pgadmin4-debuginfo
pgadmin4
pgadmin4-web-uwsgi
pgadmin4-web
pgadmin4-doc
pgadmin4-cloud
pgadmin4-desktop
system-user-pgadmin
How to mitigate CVE-2025-27152
Event Processing - update to 1.4.0
IBM Concert Software - update to 2.0.0
Voice Gateway - update to 1.0.8.25
Netcool Operations Insight - update to 1.6.15
Software Support app (Android) - update to 2.0.2
Storage Defender - Resiliency Service - update to 2.0.13
watsonx.data - update to 2.1.3
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.0
Security QRadar EDR - update to 3.12.17
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.0.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
strapi - update to 4.25.22
Cloud Pak for Data - update to 5.2
Knowledge Catalog Premium Cartridge - update to 5.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.1
Storage Ceph - update to 8.1z1
Db2 Big SQL - update to 7.8.2
Maximo Application Suite - Monitor Component - addressed in versions 8.10.21, 8.11.19, 9.0.11
IBM Maximo Application Suite - addressed in versions 8.10.25, 8.11.22, 9.0.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.17, 9.0.9
IBM Business Automation Manager Open Editions - update to 9.2.1
IBM License Metric Tool - update to 9.2.39
Bamboo Server - addressed in versions 9.6.20, 10.2.12, 11.0.8
Jira Software Server - update to 10.3.13
Jira Software Data Center - update to 10.3.13
Event Streams - update to 11.8.0
IBM Robotic Process Automation - addressed in versions 21.0.7.21, 23.0.20.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
IBM Automation Decision Services - update to 24.0.0.0.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
IBM Observability with Instana - update to 1.0.293
IBM Cloud Pak for Security - update to 1.11.2.0
QRadar Deployment Intelligence App - update to 3.0.17
Telco Unified OSS Console - update to 3.1.15
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.9, 5.2.0
pgadmin4-debuginfo - update to 4.30-150300.3.18.1
pgadmin4 - addressed in versions 4.30-150300.3.18.1, 8.5-150600.3.9.1
pgadmin4-web-uwsgi - addressed in versions 4.30-150300.3.18.1, 8.5-150600.3.9.1
pgadmin4-web - update to 4.30-150300.3.18.1
pgadmin4-doc - addressed in versions 4.30-150300.3.18.1, 8.5-150600.3.9.1
pgadmin4-cloud - update to 8.5-150600.3.9.1
pgadmin4-desktop - update to 8.5-150600.3.9.1
system-user-pgadmin - update to 8.5-150600.3.9.1
Maximo Application Suite - IoT Component - addressed in versions 8.7.24, 8.8.20, 9.0.10, 9.1.1
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.11.0
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- SSRF in Axios
- Multiple vulnerabilities in IBM License Metric Tool
- Strapi update for axios
- Multiple vulnerabilities in IBM Software Support app (Android)
- SUSE update for pgadmin4
- SUSE update for pgadmin4
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Business Automation Workflow
- IBM watsonx.data update for axios
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Security QRadar EDR
- IBM Watson Discovery update for axios
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Fusion
- IBM Event Processing update for axios
- IBM Event Streams update for axios
- IBM Robotic Process Automation for Cloud Pak update for axios
- IBM Cloud Pak for Data update for axios
- IBM Edge Data Collector update for axios
- IBM Maximo Application Suite - Monitor Component update for axios
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence app
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in HPE Telco Unified OSS Console
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Business Automation Insights
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for axios
- IBM Storage Ceph update for axios
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- SUSE update for pgadmin4
- SUSE update for pgadmin4
- Multiple vulnerabilities in IBM Concert Software
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for axios
- Multiple vulnerabilities in IBM Security SOAR
- Multiple vulnerabilities in Netcool Operations Insight
- Jira Software Data Center and Server update for axios
- Bamboo Data Center and Server update for axios
- IBM Db2 Big SQL on Cloud Pak for Data update for axios
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge