Heap-based buffer overflow in IBM Semeru Runtimes - CVE-2025-2900

 

Heap-based buffer overflow in IBM Semeru Runtimes - CVE-2025-2900

Published: July 3, 2025


Vulnerability identifier: #VU112130
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2900
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a defect in its native AES/CBC encryption implementation. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

IBM Semeru Runtimes
Data Product Hub
Cognos Dashboards on Cloud Pak for Data
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
DB2 Query Management Facility
Host On-Demand
z/Transaction Processing Facility ( z/TPF)
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
IBM Tivoli Netcool Impact
IBM SPSS Collaboration and Deployment Services
IBM Power Hardware Management Console (HMC)
IBM Sterling Transformation Extender
IBM Sterling Connect:Direct FTP+
IBM Sterling Connect:Direct for UNIX
SPSS Statistics
IBM DataPower Gateway
IBM Sterling Connect:Direct File Agent
IBM Enterprise Content Management System Monitor
IBM Cognos Controller
Rational Business Developer (RBD)
java-21-ibm-semeru-certified-jdk (Red Hat package)

How to mitigate CVE-2025-2900

Install updates from vendor's website.

IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
Data Product Hub - update to 5.2.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Cognos Dashboards on Cloud Pak for Data - update to 5.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.2.0.28, 6.3.0.14, 6.4.0.3
IBM Sterling Control Center - addressed in versions 6.3.1.0.5, 6.4.0.0.2
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Power Hardware Management Console (HMC) - update to 10.3.1060.0 SP2
IBM DataPower Gateway - addressed in versions 10.5.0.18, 10.6.0.6, 10.6.4.0
IBM Cognos Controller - update to 11.1.2
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.0.31
IBM Sterling Connect:Direct File Agent - update to 1.4.0.4
IBM Enterprise Content Management System Monitor - update to 5.6.000 FP4
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.5, 6.4.0.2
Rational Business Developer (RBD) - addressed in versions 9.6.2, 9.7.2
Host On-Demand - update to 15.0.4
java-21-ibm-semeru-certified-jdk (Red Hat package) - update to 21.0.7.0.6-1.el10_0
SPSS Statistics - addressed in versions 28.0.1.1 IF017, 29.0.2.0 IF018, 30.0.0.0 IF014, 31.0.2.0 IF06

External References

Related Security Bulletins