Protection Mechanism Failure in Apache Parquet Java - CVE-2025-46762
Published: May 2, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when parsing Avro schema from a Parquet file metadata. A remote attacker can trick the victim into installing a malicious package and execute arbitrary code on the system.
Note, the default setting of trusted packages still allows malicious classes from these packages to be executed.
Affected software
watsonx.data
Watson Query on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Oracle Business Intelligence Enterprise Edition
User Entity Behavior Analytics
Db2 Big SQL
How to mitigate CVE-2025-46762
watsonx.data - update to 2.2.1
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 3.2.1
User Entity Behavior Analytics - update to 5.0.2
Db2 Big SQL - update to 8.2.1
External References
Related Security Bulletins
- Remote code execution in Apache Parquet Java
- Multiple vulnerabilities in IBM Data Virtualization on IBM Software Hub
- IBM watsonx.data update for Apache Parquet
- Multiple vulnerabilities in IBM User Entity Behavior Analytics
- IBM Db2 Big SQL on Cloud Pak for Data update for Apache Parquet
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition