Uncaught Exception in multer - CVE-2025-7338

 

Uncaught Exception in multer - CVE-2025-7338

Published: July 18, 2025


Vulnerability identifier: #VU113032
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7338
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncaught exception. A remote user can send a specially crafted multi-part upload request and perform a denial of service (DoS) attack.


Affected software

multer
watsonx Orchestrate Developer Edition
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
WatsonX BI Assistant
IBM OpenPages with Watson
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM API Connect
IBM QRadar Data Synchronization App

How to mitigate CVE-2025-7338

Install updates from vendor's website.

multer - update to 2.0.2
Netcool Operations Insight - update to 1.6.15
watsonx Orchestrate Developer Edition - update to 1.13.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
WatsonX BI Assistant - update to 5.2.1
IBM OpenPages with Watson - addressed in versions 9.0.0.5, 9.1.2
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM QRadar Data Synchronization App - update to 3.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1

External References

Related Security Bulletins