Use of insufficiently random values in form-data - CVE-2025-7783

 

Use of insufficiently random values in form-data - CVE-2025-7783

Published: July 23, 2025 / Updated: August 15, 2025


Vulnerability identifier: #VU113173
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7783
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform parameter injection attacks.

The vulnerability exists due to software uses a weak Math.random() method to generated random values for multipart form-encoded data. A remote attacker can observe values produced by Math.random in the target application and predict the random number used to generate form-data's boundary value and inject arbitrary parameters into requests. 


Affected software

form-data
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
Ubuntu
openEuler
Astronomer with IBM
QRadar Investigation Assistant
DataPower Operations Dashboard
Db2 Intelligence Center
Storage Sentinel Anomaly Scan Engine
watsonx Orchestrate Developer Edition
SOAR App Host
Watson Query on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
DB2 Data Management Console
Data Product Hub
WatsonX BI Assistant
MongoDB Enterprise Advanced with IBM
Db2 Big SQL
IBM OpenPages with Watson
Maximo Application Suite - Monitor Component
Maximo Application Suite Ai Service
Rational Performance Tester
Rational Developer for i
DevOps Test Performance
InfoSphere Optim Archive Viewer
Business Automation Insights
Qlik Sense Enterprise for Windows
QRadar Deployment Intelligence App
QRadar Hub
Application Modernization Accelerator
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Maximo Application Suite - Edge Data Collector
IBM Security QRadar Log Management AQL Plugin
IBM Cloud Transformation Advisor
IBM Fusion HCI
Red Hat Advanced Cluster Management for Kubernetes
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
Crowd Data Center
IBM Sterling External Authentication Server
IBM Rational Build Forge
IBM Maximo Application Suite
IBM Robotic Process Automation
IBM Business Automation Workflow
IBM Automation Decision Services
IBM Cloud Pak for Business Automation
Voice Gateway
axios
IBM API Connect
IBM Security SOAR
IBM Security QRadar Analyst Workflow
node-form-data (Ubuntu package)
nodejs-form-data
yarnpkg
nodejs18-debuginfo
nodejs18
nodejs18-devel
npm18
nodejs18-debugsource
nodejs18-docs
Multicluster Engine for Kubernetes
IBM QRadar Data Synchronization App
IBM App Connect Enterprise

How to mitigate CVE-2025-7783

Install updates from vendor's website.

form-data - addressed in versions 2.5.4, 3.0.4, 4.0.4
Astronomer with IBM - update to 1.1.0
IBM Security QRadar Log Management AQL Plugin - update to 1.1.4
QRadar Investigation Assistant - update to 1.1.1
Voice Gateway - update to 1.0.8.26
DataPower Operations Dashboard - update to 1.0.23.3
Db2 Intelligence Center - update to 1.1.2.0
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
watsonx Orchestrate Developer Edition - update to 1.14.0
axios - update to 1.11.0
SOAR App Host - update to 1.15.6.1
IBM Cloud Transformation Advisor - update to 4.4.0
IBM Fusion HCI - update to 2.11.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.12.5, 2.13.4
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 3.2.1
DB2 Data Management Console - update to 3.1.13.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
Data Product Hub - update to 5.2.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.2
WatsonX BI Assistant - update to 5.2.1
IBM Spectrum Control - update to 5.4.13.2
Crowd Data Center - addressed in versions 6.0.10, 6.1.6, 6.2.5, 6.3.2
IBM Sterling External Authentication Server - addressed in versions 6.1.0.3, 6.1.1.1
Db2 Big SQL - update to 8.2.1
IBM Rational Build Forge - update to 8.0.0.29
IBM OpenPages with Watson - addressed in versions 8.3.0.3.3, 9.0.0.5.6, 9.1.2
IBM Maximo Application Suite - addressed in versions 8.10.29, 8.11.26, 9.0.15, 9.1.3
Maximo Application Suite - Monitor Component - addressed in versions 8.10.25, 8.11.23, 9.0.15, 9.1.5
Maximo Application Suite Ai Service - update to 9.1.10
IBM API Connect - update to 10.0.8.5
DevOps Test Performance - update to 11.0.8
InfoSphere Optim Archive Viewer - update to 11.7 FixPack13
IBM Robotic Process Automation - addressed in versions 23.0.20.4, 30.0.0.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF001
Business Automation Insights - update to 25.0.0.0.1
IBM Security SOAR - update to 51.0.7.1
Qlik Sense Enterprise for Windows - addressed in versions May 2025 Patch 6, November 2024 Patch 18, May 2024 Patch 24
node-form-data (Ubuntu package) - addressed in versions 0.1.0-1ubuntu0.14.04.1~esm1, 0.1.0-1ubuntu0.16.04.1~esm1, 0.1.0-1ubuntu0.18.04.1~esm1, 3.0.0-2ubuntu0.1~esm1, 3.0.1-1ubuntu0.1~esm1, 4.0.0-1ubuntu0.1
nodejs-form-data - update to 0.2.0-2
yarnpkg - addressed in versions 1.22.22-11.el9, 1.22.22-11.el10_1, 1.22.22-11.fc41, 1.22.22-11.fc42
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.7.6, 2.8.3
IBM Security QRadar Analyst Workflow - update to 3.0.1
QRadar Deployment Intelligence App - update to 3.0.19
IBM QRadar Data Synchronization App - update to 3.2.2
QRadar Hub - update to 3.9.0
Application Modernization Accelerator - update to 4.4.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.21, 9.0.13, 9.1.3
IBM App Connect Enterprise - addressed in versions 12.0.16, 12.15.0
nodejs18-debuginfo - update to 18.20.8-8.41.1
nodejs18 - update to 18.20.8-8.41.1
nodejs18-devel - update to 18.20.8-8.41.1
npm18 - update to 18.20.8-8.41.1
nodejs18-debugsource - update to 18.20.8-8.41.1
nodejs18-docs - update to 18.20.8-8.41.1
IBM Automation Decision Services - addressed in versions 23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF004, 25.0.0-IF001

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins