Heap-based buffer overflow in IBM Semeru Runtimes - CVE-2025-2900
Published: July 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a defect in its native AES/CBC encryption implementation. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Data Product Hub
Cognos Dashboards on Cloud Pak for Data
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
DB2 Query Management Facility
Host On-Demand
z/Transaction Processing Facility ( z/TPF)
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
IBM Tivoli Netcool Impact
IBM SPSS Collaboration and Deployment Services
IBM Power Hardware Management Console (HMC)
IBM Sterling Transformation Extender
IBM Sterling Connect:Direct FTP+
IBM Sterling Connect:Direct for UNIX
SPSS Statistics
IBM DataPower Gateway
IBM Sterling Connect:Direct File Agent
IBM Enterprise Content Management System Monitor
IBM Cognos Controller
Rational Business Developer (RBD)
java-21-ibm-semeru-certified-jdk (Red Hat package)
How to mitigate CVE-2025-2900
Data Product Hub - update to 5.2.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Cognos Dashboards on Cloud Pak for Data - update to 5.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.2.0.28, 6.3.0.14, 6.4.0.3
IBM Sterling Control Center - addressed in versions 6.3.1.0.5, 6.4.0.0.2
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Power Hardware Management Console (HMC) - update to 10.3.1060.0 SP2
IBM DataPower Gateway - addressed in versions 10.5.0.18, 10.6.0.6, 10.6.4.0
IBM Cognos Controller - update to 11.1.2
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.0.31
IBM Sterling Connect:Direct File Agent - update to 1.4.0.4
IBM Enterprise Content Management System Monitor - update to 5.6.000 FP4
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.5, 6.4.0.2
Rational Business Developer (RBD) - addressed in versions 9.6.2, 9.7.2
Host On-Demand - update to 15.0.4
java-21-ibm-semeru-certified-jdk (Red Hat package) - update to 21.0.7.0.6-1.el10_0
SPSS Statistics - addressed in versions 28.0.1.1 IF017, 29.0.2.0 IF018, 30.0.0.0 IF014, 31.0.2.0 IF06
External References
Related Security Bulletins
- Heap-based buffer overflow in IBM Semeru Runtime
- Multiple vulnerabilities in IBM Sterling Connect:Direct File Agent
- Red Hat Enterprise Linux 10 update for java-21-ibm-semeru-certified-jdk
- Multiple vulnerabilities in IBM Sterling Transformation Extender
- Multiple vulnerabilities in IBM DataPower Gateway
- Multiple vulnerabilities in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Sterling Connect:Direct FTP+
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms and IBM CICS Transaction Gateway Desktop Edition
- IBM SPSS Collaboration and Deployment Services update for IBM Semeru Runtime
- IBM Db2 Query Management Facility update for IBM Semeru Runtime
- Multiple vulnerabilities in IBM z/Transaction Processing Facility
- Heap-based buffer overflow in IBM Rational Business Developer
- Multiple vulnerabilities in IBM Data Product Hub
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Heap-based buffer overflow in IBM OpenPages
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in IBM Enterprise Content Management System Monitor
- Multiple vulnerabilities in IBM Controller
- Multiple vulnerabilities in IBM SPSS Statistics Client and Server
- Multiple vulnerabilities in IBM Host On-Demand
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem