Security features bypass in Spring Framework - CVE-2025-22233

 

Security features bypass in Spring Framework - CVE-2025-22233

Published: May 16, 2025


Vulnerability identifier: #VU109251
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22233
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to String.toLowerCase() has some Locale dependent exceptions when handling case insensitive patterns in DataBinder. A remote attacker can bypass implemented security restrictions by passing specially crafted data to the application.

Note, the vulnerability exists due to incomplete fix for #VU98795 (CVE-2024-38820).


Affected software

Spring Framework
IBM Observability with Instana
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Sterling Connect:Direct Web Services
IBM Common Licensing
IBM Security Verify Governance
IBM SPSS Collaboration and Deployment Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
watsonx.data
DB2 Data Management Console
Guardium Data Security Center (GDSC)
OpenPages for IBM Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Business Automation Manager Open Editions
OpenPages Cloud pak for data service version
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Cloudera Observability with IBM
IBM Sterling File Gateway
Oracle Commerce Guided Search
Oracle Commerce Platform
Library Support for Spring
Operational Decision Manager

How to mitigate CVE-2025-22233

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.43, 6.0.28, 6.1.20, 6.2.7
IBM Observability with Instana - update to 1.0.297
watsonx.data - update to 2.2.2
DB2 Data Management Console - update to 3.1.13.2
Guardium Data Security Center (GDSC) - update to 3.8.1
OpenPages for IBM Cloud Pak for Data - update to 5.3.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.0.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.14, 6.4.0.3
IBM Common Licensing - update to 9.0.0.2
IBM Business Automation Manager Open Editions - update to 9.2.1
OpenPages Cloud pak for data service version - update to 9.6.0
IBM Security Verify Governance - update to 10.0.2.0.7
Library Support for Spring - update to 2.7.29
Cloudera Observability with IBM - update to 3.6.2
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.1
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7
IBM Business Automation Workflow - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001

External References

Related Security Bulletins