Exposure of Resource to Wrong Sphere in Quarkus - CVE-2025-49574

 

Exposure of Resource to Wrong Sphere in Quarkus - CVE-2025-49574

Published: August 12, 2025 / Updated: May 5, 2026


Vulnerability identifier: #VU113811
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49574
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to an error when duplicating a duplicated context. A remote user can gain access to sensitive information, such as request scope, security details, and metadata.


Affected software

Quarkus
Event Processing
DataPower Operations Dashboard
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Event Endpoint Management
Business Automation Insights
IBM Concert Software
IBM Observability with Instana
IBM Automation Decision Services
IBM Cloud Pak for Business Automation
Event Streams
AMQ Streams

How to mitigate CVE-2025-49574

Install updates from vendor's website.

Quarkus - addressed in versions 3.15.7, 3.20.3, 3.24.1
Event Processing - update to 1.4.5
IBM Concert Software - update to 2.2.0
DataPower Operations Dashboard - update to 1.0.23.2
IBM Observability with Instana - update to 1.0.307
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
IBM Event Endpoint Management - update to 11.7.0
Event Streams - update to 12.2.1
AMQ Streams - update to 3.1.0
IBM Automation Decision Services - addressed in versions 23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.5, 25.0.0.0.1

External References

Related Security Bulletins