Buffer overflow in jackson-core - CVE-2025-52999

 

Buffer overflow in jackson-core - CVE-2025-52999

Published: July 2, 2025


Vulnerability identifier: #VU112106
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-52999
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when parsing deeply nested JSON files. A remote attacker can pass a specially crafted JSON file to the application, trigger memory corruption and perform a denial of service (DoS) attack.


Affected software

jackson-core
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
Operations Analytics - Log Analysis
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Watson Query on Cloud Pak for Data
Storage Defender Copy Data Management
Cloudera Observability with IBM
Oracle Business Intelligence Enterprise Edition
Maximo Application Suite - IoT Component
Datacap
Rational Performance Tester
DevOps Test Performance
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Netcool Operations Insight
PowerVC
Bitbucket Data Center
Crucible Server
Crucible Data Center
IBM Watson Discovery for IBM Cloud Pak for Data
Crowd Data Center
IBM Spectrum Symphony
IBM Common Licensing
Enterprise Manager Base Platform
Primavera P6 Enterprise Project Portfolio Management
IBM Business Automation Workflow
Financial Transaction Manager for ACH Services and Check Services
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
Bitbucket Server
JBoss Enterprise Application Platform
OpenShift Developer Tools and Services
Communications Unified Assurance
Crowd Server
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
xsom
bea-stax-api
glassfish-fastinfoset
xml-commons-resolver
xml-commons-apis
eap7-undertow (Red Hat package)
xmlstreambuffer
eap7-jboss-server-migration (Red Hat package)
stax-ex
velocity
slf4j
slf4j-jdk14
glassfish-jaxb-txw2
glassfish-jaxb-runtime
glassfish-jaxb-core
glassfish-jaxb-api
apache-commons-lang
xalan-j2
eap7-jackson-annotations (Red Hat package)
eap7-jackson-modules-java8 (Red Hat package)
eap7-jackson-jaxrs-providers (Red Hat package)
eap7-jackson-module-jaxb-annotations (Red Hat package)
eap7-jackson-core (Red Hat package)
eap7-jackson-modules-base (Red Hat package)
eap7-jackson-databind (Red Hat package)
xerces-j2
jackson-core (Debian package)
jackson-annotations
jackson-modules-base
jackson-databind
jackson-jaxrs-json-provider
jackson-jaxrs-providers
jackson-module-jaxb-annotations
jackson-core
jackson-parent
jackson-bom
jenkins (Red Hat package)
resteasy
jakarta-commons-httpclient
apache-commons-collections
apache-commons-net
javassist-javadoc
javassist
eap7-netty (Red Hat package)
jenkins-2-plugins (Red Hat package)
eap7-wildfly (Red Hat package)
pki-servlet-engine
fasterxml-oss-parent
relaxngDatatype
Splunk Enterprise
Oracle Business Process Management Suite

How to mitigate CVE-2025-52999

Install updates from vendor's website.

jackson-core - update to 2.15.0
Operations Analytics - Log Analysis - update to 1.3.8.4
Netcool Operations Insight - update to 1.6.15
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 3.2.0
Watson Query on Cloud Pak for Data - update to 3.2.0
PowerVC - addressed in versions 2.2.1.2, 2.3.0
Storage Defender Copy Data Management - update to 2.3.1.0
IBM Cloud Pak System - update to 2.3.6.0
Bitbucket Server - addressed in versions 8.19.26, 9.4.15
Bitbucket Data Center - addressed in versions 8.19.26, 9.4.15
Cloudera Observability with IBM - update to 3.6.2
Crucible Server - update to 4.9.10
Crucible Data Center - update to 4.9.10
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
JBoss Enterprise Application Platform - addressed in versions 7.1.13, 7.3.16, 7.4.23
Crowd Server - update to 7.1.1
Crowd Data Center - update to 7.1.1
IBM Spectrum Symphony - update to 7.3.2 FP3
Maximo Application Suite - IoT Component - addressed in versions 8.7.28, 8.8.24, 9.0.14, 9.1.5
Splunk Enterprise - addressed in versions 9.2.8, 9.2.9, 9.3.6, 9.3.7, 9.4.4, 9.4.5, 10.0.1
IBM Common Licensing - update to 9.0.0.2
Datacap - update to 9.1.10
DevOps Test Performance - update to 11.0.7
xsom - update to 0-19.20110809svn
bea-stax-api - update to 1.2.0-16
glassfish-fastinfoset - update to 1.2.13-9
xml-commons-resolver - update to 1.2-26
xml-commons-apis - update to 1.4.01-25
eap7-undertow (Red Hat package) - addressed in versions 1.4.18-18.SP16_redhat_00001.1.ep7.el7, 2.0.41-6.SP7_redhat_00001.1.el7eap
xmlstreambuffer - update to 1.5.4-8
eap7-jboss-server-migration (Red Hat package) - update to 1.7.2-20.Final_redhat_00021.1.el7eap
stax-ex - update to 1.7.7-8
velocity - update to 1.7-24
slf4j - update to 1.7.25-4
slf4j-jdk14 - update to 1.7.25-4
glassfish-jaxb-txw2 - update to 2.2.11-12
glassfish-jaxb-runtime - update to 2.2.11-12
glassfish-jaxb-core - update to 2.2.11-12
glassfish-jaxb-api - update to 2.2.12-8
apache-commons-lang - update to 2.6-21
xalan-j2 - update to 2.7.1-38
eap7-jackson-annotations (Red Hat package) - addressed in versions 2.8.11-2.redhat_00004.1.ep7.el7, 2.10.4-4.redhat_00008.1.el7eap
eap7-jackson-modules-java8 (Red Hat package) - addressed in versions 2.8.11-2.redhat_00004.1.ep7.el7, 2.10.4-3.redhat_00008.1.el7eap
eap7-jackson-jaxrs-providers (Red Hat package) - addressed in versions 2.8.11-3.redhat_00004.1.ep7.el7, 2.10.4-4.redhat_00008.1.el7eap
eap7-jackson-module-jaxb-annotations (Red Hat package) - update to 2.8.11-3.redhat_00004.1.ep7.el7
eap7-jackson-core (Red Hat package) - addressed in versions 2.8.11-3.redhat_00004.1.ep7.el7, 2.10.4-4.redhat_00008.1.el7eap
eap7-jackson-modules-base (Red Hat package) - update to 2.10.4-6.redhat_00008.1.el7eap
eap7-jackson-databind (Red Hat package) - update to 2.10.4-6.redhat_00008.1.el7eap
xerces-j2 - update to 2.11.0-34
jackson-core (Debian package) - addressed in versions 2.14.1-2~deb12u1, 2.14.1-2~deb13u1
jackson-annotations - update to 2.19.1-1
jackson-modules-base - update to 2.19.1-1
jackson-databind - update to 2.19.1-1
jackson-jaxrs-json-provider - update to 2.19.1-1
jackson-jaxrs-providers - update to 2.19.1-1
jackson-module-jaxb-annotations - update to 2.19.1-1
jackson-core - update to 2.19.1-1
jackson-parent - update to 2.19.1-1
jackson-bom - update to 2.19.1-1
jenkins (Red Hat package) - addressed in versions 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
resteasy - update to 3.0.26-7
jakarta-commons-httpclient - update to 3.1-28
apache-commons-collections - update to 3.2.2-10
apache-commons-net - update to 3.6-3
javassist-javadoc - update to 3.18.1-8
javassist - update to 3.18.1-8
eap7-netty (Red Hat package) - addressed in versions 4.1.63-3.Final_redhat_00004.1.ep7.el7, 4.1.63-6.Final_redhat_00004.1.el7eap
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1750933270-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9
eap7-wildfly (Red Hat package) - addressed in versions 7.1.13-6.GA_redhat_00002.1.ep7.el7, 7.3.16-3.GA_redhat_00003.1.el7eap
Red Hat Single Sign-On - update to 7.6.12
pki-servlet-engine - update to 9.0.62-1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF004, 25.0.0-IF001
fasterxml-oss-parent - update to 69-1
relaxngDatatype - update to 2011.1-7

External References

Related Security Bulletins