Path traversal in Spring Framework - CVE-2025-41242

 

Path traversal in Spring Framework - CVE-2025-41242

Published: August 14, 2025


Vulnerability identifier: #VU114067
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41242
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.

Note, the vulnerability affects installations when deployed on a non-compliant Servlet container.

An application can be vulnerable when all the following are true:



Affected software

Spring Framework
IBM Observability with Instana
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling B2B Integrator
IBM Spectrum Symphony
Oracle Enterprise Command Center Framework
IBM Business Automation Workflow
IBM Sterling Connect:Direct Web Services
OpenPages for IBM Cloud Pak for Data
UrbanCode Build
DevOps
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Terracotta
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
StreamSets Data Collector
IBM OpenPages with Watson
IBM Sterling File Gateway
IBM Cognos Controller
Library Support for Spring

How to mitigate CVE-2025-41242

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.44, 6.1.22, 6.2.10
IBM Observability with Instana - update to 1.0.309
IBM Process Mining - update to 2.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.2
OpenPages for IBM Cloud Pak for Data - update to 5.2.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
DevOps - update to 7.1.0.2
IBM Spectrum Symphony - update to 7.3.2 FP3
OpenPages Cloud pak for data service version - update to 9.5.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Terracotta - update to 11.1.0
IBM Cognos Controller - update to 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
Library Support for Spring - update to 2.7.29
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.15, 6.4.0.4
StreamSets Data Collector - update to 7.1.0
IBM OpenPages with Watson - addressed in versions 9.0.0.5.7, 9.1.2.1

External References

Related Security Bulletins