Information disclosure in Reactor Netty - CVE-2025-22227

 

Information disclosure in Reactor Netty - CVE-2025-22227

Published: July 17, 2025


Vulnerability identifier: #VU113023
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22227
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to Reactor Netty HTTP client leaks credentials in some specific scenarios with chained redirects. A remote attacker can gain access to sensitive information. 


Affected software

Reactor Netty
Netezza Appliance
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Observability with Instana
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Cloud Pak for Business Automation
IBM Sterling File Gateway
Operational Decision Manager

How to mitigate CVE-2025-22227

Install updates from vendor's website.

Reactor Netty - addressed in versions 1.0.49, 1.1.32, 1.2.8, 1.3.0-M5
Netezza Appliance - update to 1.0.0.1
IBM Observability with Instana - update to 1.0.299
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.2
IBM Sterling File Gateway - addressed in versions 6.2.0.5.1, 6.2.1.1.1
IBM Sterling B2B Integrator - addressed in versions 6.2.0.5.1, 6.2.1.1.1
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7

External References

Related Security Bulletins