Improper Encoding or Escaping of Output in IBM Security Guardium - CVE-2025-25029
Published: May 28, 2025
Vulnerability identifier: #VU109898
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-25029
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote privileged user can download any file on the system due to improper escaping of input.
Affected software
IBM Security Guardium
Guardium Data Protection
Guardium Data Protection
How to mitigate CVE-2025-25029
Install updates from vendor's website.
IBM Security Guardium - update to 12.0p40
Guardium Data Protection - update to 12.0p40
Guardium Data Protection - update to 12.0p40