Missing authorization in spring-boot - CVE-2025-22235

 

Missing authorization in spring-boot - CVE-2025-22235

Published: April 25, 2025


Vulnerability identifier: #VU107966
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22235
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in EndpointRequest.to() implementation. The function creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. A remote non-authenticated attacker can gain unauthorized access to the application.


Affected software

spring-boot
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Observability with Instana
Netcool Operations Insight
IBM Cloud Pak for Security
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
Bitbucket Data Center
IBM Cloud Pak for Business Automation
QRadar Suite
watsonx.data
Guardium Data Security Center (GDSC)
DevOps Solution Workbench
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
IBM Sterling File Gateway
Bitbucket Server
Library Support for Spring
Operational Decision Manager

How to mitigate CVE-2025-22235

Install updates from vendor's website.

spring-boot - addressed in versions 2.7.25, 3.1.16, 3.2.14, 3.3.11, 3.4.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
IBM Observability with Instana - update to 1.0.297
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
watsonx.data - update to 2.2.1
Guardium Data Security Center (GDSC) - update to 3.7.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Sterling Control Center - addressed in versions 6.3.1.0.4, 6.4.0.0.2
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
Library Support for Spring - update to 2.7.29
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7

External References

Related Security Bulletins