Input validation error in PBKDF2 - CVE-2025-6547
Published: June 25, 2025
Vulnerability identifier: #VU111943
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-6547
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input as the application silently disregards Uint8Array input. A remote attacker can spoof signature.
Affected software
PBKDF2
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
IBM Cloud Pak for Security
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
OpenShift Pipelines
Knowledge Catalog Premium Cartridge
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
local-npm-registry
python311-pluggy
yarnpkg
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python311-coverage-debuginfo
python311-coverage
python-coverage-debugsource
python311-pytest
QRadar Suite
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
IBM Cloud Pak for Security
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
OpenShift Pipelines
Knowledge Catalog Premium Cartridge
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
local-npm-registry
python311-pluggy
yarnpkg
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python311-coverage-debuginfo
python311-coverage
python-coverage-debugsource
python311-pytest
QRadar Suite
How to mitigate CVE-2025-6547
Install updates from vendor's website.
PBKDF2 - update to 3.1.3
IBM Cloud Pak for Security - update to 1.11.9.0
IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
local-npm-registry - update to 1.1.0-150400.9.3.1
python311-pluggy - update to 1.5.0-150400.14.10.1
QRadar Suite - update to 1.11.9.0
OpenShift Pipelines - update to 1.19.4
yarnpkg - addressed in versions 1.22.22-9.el8, 1.22.22-9.el9, 1.22.22-9.el10_1, 1.22.22-9.fc41, 1.22.22-9.fc42
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
watsonx Assistant Cartridge - update to 5.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
python311-pytest-cov - update to 6.2.1-150400.12.6.1
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-pytest - update to 8.3.5-150400.3.9.1
IBM Cloud Pak for Security - update to 1.11.9.0
IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
local-npm-registry - update to 1.1.0-150400.9.3.1
python311-pluggy - update to 1.5.0-150400.14.10.1
QRadar Suite - update to 1.11.9.0
OpenShift Pipelines - update to 1.19.4
yarnpkg - addressed in versions 1.22.22-9.el8, 1.22.22-9.el9, 1.22.22-9.el10_1, 1.22.22-9.fc41, 1.22.22-9.fc42
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
watsonx Assistant Cartridge - update to 5.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
python311-pytest-cov - update to 6.2.1-150400.12.6.1
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-pytest - update to 8.3.5-150400.3.9.1
External References
Related Security Bulletins
- Multiple vulnerabilities in PBKDF2
- Fedora 42 update for yarnpkg
- Fedora EPEL 10.1 update for yarnpkg
- Fedora EPEL 9 update for yarnpkg
- Fedora 41 update for yarnpkg
- Fedora EPEL 8 update for yarnpkg
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge
- SUSE update for aws-cli, local-npm-registry, python-boto3, python-botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python-pytest-cov, python-pytest-html, python-pytest-metada
- Multiple vulnerabilities in Red Hat OpenShift Pipelines Release 1.19
- Multiple vulnerabilities in IBM QRadar Suite
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem