Input validation error in Spring Framework - CVE-2025-41234

 

Input validation error in Spring Framework - CVE-2025-41234

Published: June 17, 2025


Vulnerability identifier: #VU111210
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-41234
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a reflected file download attack.

The vulnerability exists due to application sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. A remote attacker can trick the victim into downloading arbitrary files from an attacker controlled location. 


Affected software

Spring Framework
IBM Observability with Instana
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Security Verify Governance
IBM Sterling Connect:Direct Web Services
Storage Defender Copy Data Management
DB2 Data Management Console
DevOps Solution Workbench
UrbanCode Build
DevOps
Maximo Application Suite Ai Service
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
Cloudera Observability with IBM
IBM Sterling File Gateway
IBM InfoSphere Information Server

How to mitigate CVE-2025-41234

Install updates from vendor's website.

Spring Framework - addressed in versions 6.0.29, 6.1.21, 6.2.8
IBM Observability with Instana - update to 1.0.298
Storage Defender Copy Data Management - update to 2.3.1.0
DB2 Data Management Console - update to 3.1.13.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
DevOps - update to 7.1.0.2
Maximo Application Suite Ai Service - update to 9.1.1
IBM Security Verify Governance - update to 10.0.2.0.7
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Cloudera Observability with IBM - update to 3.6.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.15, 6.4.0.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1

External References

Related Security Bulletins