Resource exhaustion in Fault Tolerance - CVE-2025-2240
Published: April 3, 2025
Vulnerability identifier: #VU106927
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2240
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when calling metrics URI. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Fault Tolerance
Red Hat build of Quarkus
DataPower Operations Dashboard
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Business Automation Manager Open Editions
Telco Service Activator
Event Streams
Red Hat Camel for Spring Boot
Red Hat build of Quarkus
DataPower Operations Dashboard
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Business Automation Manager Open Editions
Telco Service Activator
Event Streams
Red Hat Camel for Spring Boot
How to mitigate CVE-2025-2240
Install updates from vendor's website.
Fault Tolerance - addressed in versions 6.4.2, 6.9.0
DataPower Operations Dashboard - update to 1.0.23.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
IBM Business Automation Manager Open Editions - update to 9.2.1
Event Streams - update to 12.2.1
Red Hat build of Quarkus - update to 3.15.4
Red Hat Camel for Spring Boot - addressed in versions 4.8, 4.8.5
Telco Service Activator - update to 10.3.0
DataPower Operations Dashboard - update to 1.0.23.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
IBM Business Automation Manager Open Editions - update to 9.2.1
Event Streams - update to 12.2.1
Red Hat build of Quarkus - update to 3.15.4
Red Hat Camel for Spring Boot - addressed in versions 4.8, 4.8.5
Telco Service Activator - update to 10.3.0
External References
Related Security Bulletins
- Remote denial of service in Smallrye Fault Tolerance
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.8
- Red Hat build of Quarkus update for Smallrye Fault Tolerance
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in HPE Telco Service Activator
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Smallrye
- DataPower Operations Dashboard update for Fault Tolerance
- IBM Event Streams update for Smallrye