Improper authorization in Spring Security - CVE-2025-22223
Published: March 19, 2025 / Updated: March 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization process.
The vulnerability exists due to an error in @EnableMethodSecurity when locating method security annotations on parameterized types or methods. A remote non-authenticated attacker can bypass authorization process and gain access to sensitive information.
Affected software
watsonx.data
Storage Defender Copy Data Management
IBM Business Automation Manager Open Editions
How to mitigate CVE-2025-22223
watsonx.data - update to 2.2
Storage Defender Copy Data Management - update to 2.3.1.0
IBM Business Automation Manager Open Editions - update to 9.2.1