Uncaught Exception in multer - CVE-2025-48997

 

Uncaught Exception in multer - CVE-2025-48997

Published: July 25, 2025


Vulnerability identifier: #VU113227
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48997
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to unhandled exception, leading to a crash of the process. A remote attacker can trigger a Denial of Service (DoS) by sending an upload file request with an empty string field name. This request causes an unhandled exception, leading to a crash of the process.


Affected software

multer
watsonx Orchestrate Developer Edition
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Business Automation Insights
IBM Concert Software
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Cloud Pak for Business Automation
IBM App Connect Enterprise
IBM QRadar Data Synchronization App

How to mitigate CVE-2025-48997

Install updates from vendor's website.

multer - update to 2.0.1
IBM Concert Software - update to 2.0.0
watsonx Orchestrate Developer Edition - update to 1.13.0
Netcool Operations Insight - update to 1.6.15
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
IBM Spectrum Control - update to 5.4.13.2
IBM App Connect Enterprise - addressed in versions 12.0.12.16, 13.0.4.0
IBM QRadar Data Synchronization App - update to 3.3.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.5, 25.0.0.0.1

External References

Related Security Bulletins