Security features bypass in Spring Security - CVE-2025-22228
Published: March 19, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to BCryptPasswordEncoder does not properly enforce maximum password length and will return "true" for passwords larger than 72 characters as long as the first 72 characters are the same. This can be used set weak passwords that can be easily brute-forced.
Affected software
Netcool Operations Insight
Crucible Server
Crucible Data Center
Jira Service Management Data Center
Jira Service Management Server
IBM Sterling Control Center
Confluence Data Center
Bitbucket Data Center
IBM Common Licensing
Bamboo Server
Jira Software Data Center
IBM Cloud Pak for Business Automation
IBM Cloud Object Storage Systems
watsonx.data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
DevOps Solution Workbench
IBM Business Automation Manager Open Editions
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
Confluence Server
Bitbucket Server
Jira Software Server
Oracle Banking Liquidity Management
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
Operational Decision Manager
How to mitigate CVE-2025-22228
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Crucible Server - update to 4.9.11
Crucible Data Center - update to 4.9.11
Jira Service Management Data Center - addressed in versions 5.12.24, 10.3.7, 10.7.1
Jira Service Management Server - addressed in versions 5.12.24, 10.3.7, 10.7.1
IBM Sterling Control Center - addressed in versions 6.3.1.0.4, 6.4.0.0.2
Confluence Data Center - addressed in versions 8.5.23, 9.2.5, 9.5.1
Confluence Server - addressed in versions 8.5.23, 9.2.5, 9.5.1
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
IBM Business Automation Manager Open Editions - update to 9.2.1
IBM Common Licensing - update to 9.0.0.2
Bamboo Server - addressed in versions 9.6.14, 10.2.3
Jira Software Server - addressed in versions 9.12.24, 10.3.7, 10.7.1
Jira Software Data Center - addressed in versions 9.12.24, 10.3.7, 10.7.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
jenkins (Red Hat package) - addressed in versions 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8
IBM Cloud Object Storage Systems - addressed in versions 3.19.0.54, 3.19.2.72
Red Hat Camel for Spring Boot - update to 4.8.5
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1750933270-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7
External References
Related Security Bulletins
- Multiple vulnerabilities in Spring Security
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.8
- IBM watsonx.data update for Spring Framework
- Confluence Data Center and Server update for Spring Security
- Bamboo Data Center update for Spring Security
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCPTools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for spring-security-crypto
- Jira Software Data Center and Server update for spring-security-crypto
- Jira Service Management Data Center and Server update for spring-security-crypto
- Multiple vulnerabilities in IBM Cloud Object System
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM DevOps Solution Workbench
- Bitbucket Data Center and Server update for Spring Security
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Crucible Data Center and Crucible Server