Resource exhaustion in Apache Commons Configuration - CVE-2025-46392
Published: May 9, 2025
Vulnerability identifier: #VU108843
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46392
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when loading a specially crafted configuration file. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Apache Commons Configuration
watsonx.data
IBM Content Navigator
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Cloud Application Performance Management (APM)
IBM Business Automation Workflow
Storage Protect for Space Management
Oracle WebLogic Server
Oracle Banking Virtual Account Management
watsonx.data
IBM Content Navigator
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Cloud Application Performance Management (APM)
IBM Business Automation Workflow
Storage Protect for Space Management
Oracle WebLogic Server
Oracle Banking Virtual Account Management
How to mitigate CVE-2025-46392
Install updates from vendor's website.
Apache Commons Configuration - update to 2.0
watsonx.data - update to 2.2.1
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
Storage Protect for Space Management - update to 8.2.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.18
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF007, 25.0.0-IF003
watsonx.data - update to 2.2.1
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
Storage Protect for Space Management - update to 8.2.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.18
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF007, 25.0.0-IF003
External References
Related Security Bulletins
- Denial of service in Apache Commons Configuration
- Multiple vulnerabilities in IBM Application Performance Management
- IBM watsonx.data update for Apache Commons Configuration
- IBM Business Automation Workflow traditional update for Apache Commons Configuration
- IBM Content Navigator update for Apache Commons Configuration
- Multiple vulnerabilities in Oracle Banking Virtual Account Management
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- IBM Storage Protect for Space Management update for Apache Commons