Input validation error in Spring Framework - CVE-2025-41234
Published: June 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a reflected file download attack.
The vulnerability exists due to application sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. A remote attacker can trick the victim into downloading arbitrary files from an attacker controlled location.
Affected software
IBM Observability with Instana
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Security Verify Governance
IBM Sterling Connect:Direct Web Services
Storage Defender Copy Data Management
DB2 Data Management Console
DevOps Solution Workbench
UrbanCode Build
DevOps
Maximo Application Suite Ai Service
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
Cloudera Observability with IBM
IBM Sterling File Gateway
IBM InfoSphere Information Server
How to mitigate CVE-2025-41234
IBM Observability with Instana - update to 1.0.298
Storage Defender Copy Data Management - update to 2.3.1.0
DB2 Data Management Console - update to 3.1.13.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
DevOps - update to 7.1.0.2
Maximo Application Suite Ai Service - update to 9.1.1
IBM Security Verify Governance - update to 10.0.2.0.7
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Cloudera Observability with IBM - update to 3.6.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.15, 6.4.0.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
External References
Related Security Bulletins
- Reflected file download attack in Spring Framework
- Multiple vulnerabilities in IBM Observability with Instana
- IBM Maximo Application Suite Ai-Service Component update for Spring Framework
- Multiple vulnerabilities in IBM Business Automation Insights
- IBM InfoSphere Information Server update for Spring Framework
- IBM Sterling Connect:Direct Web Services update for Spring Framework
- Multiple vulnerabilities in IBM DevOps Solution Workbench
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM DevOps Build
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Sterling B2B Integrator and IBM Sterling File Gateway
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition