Insufficient verification of data authenticity in Spring Cloud Gateway - CVE-2025-41235
Published: May 30, 2025
Vulnerability identifier: #VU109961
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-41235
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to spoof requests origin.
The vulnerability exists due to the Spring Cloud Gateway accepts the X-Forwarded-* and Forwarded header from untrusted proxies. A remote attacker can manipulate the header information and spoof the IP address of the request source.
Affected software
Spring Cloud Gateway
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Copy Data Management
IBM Sterling File Gateway
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Copy Data Management
IBM Sterling File Gateway
How to mitigate CVE-2025-41235
Install updates from vendor's website.
Spring Cloud Gateway - addressed in versions 3.1.10, 4.0.12, 4.1.8, 4.2.3, 4.3.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.0.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Storage Copy Data Management - update to 2.2.27.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.0.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Storage Copy Data Management - update to 2.2.27.0
External References
Related Security Bulletins
- IP address spoofing in Spring Cloud Gateway Server
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Spring Cloud Gateway Server
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Spring Cloud