Improper authorization in Spring Security - CVE-2025-22223

 

Improper authorization in Spring Security - CVE-2025-22223

Published: March 19, 2025 / Updated: March 25, 2025


Vulnerability identifier: #VU105880
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22223
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization process.

The vulnerability exists due to an error in @EnableMethodSecurity when locating method security annotations on parameterized types or methods. A remote non-authenticated attacker can bypass authorization process and gain access to sensitive information.


Affected software

Spring Security
watsonx.data
Storage Defender Copy Data Management
IBM Business Automation Manager Open Editions

How to mitigate CVE-2025-22223

Install updates from vendor's website.

Spring Security - update to 6.4.4
watsonx.data - update to 2.2
Storage Defender Copy Data Management - update to 2.3.1.0
IBM Business Automation Manager Open Editions - update to 9.2.1

External References

Related Security Bulletins