Improper Authentication in Postgresql JDBC Driver - CVE-2025-49146
Published: July 4, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). A remote attacker can intercept connections that users believed were protected by channel binding requirements.
Affected software
Event Processing
DataPower Operations Dashboard
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Storage Scale
IBM Business Automation Manager Open Editions
Bitbucket Server
AMQ Broker
Bitbucket Data Center
Confluence Data Center
Bamboo Server
Oracle Enterprise Data Quality
IBM Sterling Connect:Direct Web Services
Confluence Server
Keycloak
Red Hat Camel for Spring Boot
How to mitigate CVE-2025-49146
Event Processing - update to 1.4.2
DataPower Operations Dashboard - update to 1.0.23.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Cognos Dashboards on Cloud Pak for Data - update to 5.2.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
Storage Scale - addressed in versions 5.1.9.11, 5.2.3.3, 6.2.3.2
IBM Business Automation Manager Open Editions - update to 9.2.1
Bitbucket Server - addressed in versions 9.4.8, 9.6.4
Bitbucket Data Center - addressed in versions 9.4.8, 9.6.4
Confluence Data Center - update to 9.2.11
Confluence Server - update to 9.2.11
Bamboo Server - addressed in versions 10.2.6, 11.0.3
Keycloak - update to 26.3.2
Red Hat Camel for Spring Boot - update to 4.10.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.15, 6.4.0.4
AMQ Broker - addressed in versions 7.12.5, 7.13.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.10
- Improper Authentication in Postgresql JDBC Driver
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Oracle Enterprise Data Quality
- Bamboo Data Center and Server update for Postgresql JDBC Driver
- Multiple vulnerabilities in AMQ Broker 7.13
- IBM Event Processing update for pgjdbc
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for pgjdbc
- Bitbucket Data Center and Server update for PostgreSQL JDBC driver misconfiguration
- IBM Storage Scale update for pgjdbc
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for pgjdbc
- Multiple vulnerabilities in AMQ Broker 7.12
- IBM Sterling Connect:Direct Web Services update for pgjdbc
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- DataPower Operations Dashboard update for Postgresql JDBC Driver
- Confluence Data Center and Server update for org.postgresql:postgresql
- Multiple vulnerabilities in Keycloak