Resource exhaustion in Apache Commons Configuration - CVE-2025-46392

 

Resource exhaustion in Apache Commons Configuration - CVE-2025-46392

Published: May 9, 2025


Vulnerability identifier: #VU108843
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46392
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when loading a specially crafted configuration file. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Apache Commons Configuration
watsonx.data
IBM Content Navigator
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Cloud Application Performance Management (APM)
IBM Business Automation Workflow
Storage Protect for Space Management
Oracle WebLogic Server
Oracle Banking Virtual Account Management

How to mitigate CVE-2025-46392

Install updates from vendor's website.

Apache Commons Configuration - update to 2.0
watsonx.data - update to 2.2.1
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
Storage Protect for Space Management - update to 8.2.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.18
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF007, 25.0.0-IF003

External References

Related Security Bulletins