Exposure of Resource to Wrong Sphere in Quarkus - CVE-2025-49574
Published: August 12, 2025 / Updated: May 5, 2026
Vulnerability identifier: #VU113811
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49574
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to an error when duplicating a duplicated context. A remote user can gain access to sensitive information, such as request scope, security details, and metadata.
Affected software
Quarkus
Event Processing
DataPower Operations Dashboard
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Event Endpoint Management
Business Automation Insights
IBM Concert Software
IBM Observability with Instana
IBM Automation Decision Services
IBM Cloud Pak for Business Automation
Event Streams
AMQ Streams
Event Processing
DataPower Operations Dashboard
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Event Endpoint Management
Business Automation Insights
IBM Concert Software
IBM Observability with Instana
IBM Automation Decision Services
IBM Cloud Pak for Business Automation
Event Streams
AMQ Streams
How to mitigate CVE-2025-49574
Install updates from vendor's website.
Quarkus - addressed in versions 3.15.7, 3.20.3, 3.24.1
Event Processing - update to 1.4.5
IBM Concert Software - update to 2.2.0
DataPower Operations Dashboard - update to 1.0.23.2
IBM Observability with Instana - update to 1.0.307
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
IBM Event Endpoint Management - update to 11.7.0
Event Streams - update to 12.2.1
AMQ Streams - update to 3.1.0
IBM Automation Decision Services - addressed in versions 23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.5, 25.0.0.0.1
Event Processing - update to 1.4.5
IBM Concert Software - update to 2.2.0
DataPower Operations Dashboard - update to 1.0.23.2
IBM Observability with Instana - update to 1.0.307
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
IBM Event Endpoint Management - update to 11.7.0
Event Streams - update to 12.2.1
AMQ Streams - update to 3.1.0
IBM Automation Decision Services - addressed in versions 23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.5, 25.0.0.0.1
External References
Related Security Bulletins
- Information disclosure in Quarkus
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Insights
- IBM Datapower Operations Dashboard update for Quarkus
- Red Hat AMQ Streams update for Apache Kafka
- Multiple vulnerabilities in IBM Event Processing
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Quarkus
- Multiple vulnerabilities in IBM Concert Software
- IBM Event Streams update for Quarkus
- Multiple vulnerabilities in IBM Event Endpoint Management
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Automation Decision Services