Path traversal in Spring Framework - CVE-2025-41242
Published: August 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Note, the vulnerability affects installations when deployed on a non-compliant Servlet container.
An application can be vulnerable when all the following are true:
- the application is deployed as a WAR or with an embedded Servlet container
- the Servlet container does not reject suspicious sequences
- the application serves static resources with Spring resource handling
Affected software
IBM Observability with Instana
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling B2B Integrator
IBM Spectrum Symphony
Oracle Enterprise Command Center Framework
IBM Business Automation Workflow
IBM Sterling Connect:Direct Web Services
OpenPages for IBM Cloud Pak for Data
UrbanCode Build
DevOps
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Terracotta
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
StreamSets Data Collector
IBM OpenPages with Watson
IBM Sterling File Gateway
IBM Cognos Controller
Library Support for Spring
How to mitigate CVE-2025-41242
IBM Observability with Instana - update to 1.0.309
IBM Process Mining - update to 2.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.2
OpenPages for IBM Cloud Pak for Data - update to 5.2.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
DevOps - update to 7.1.0.2
IBM Spectrum Symphony - update to 7.3.2 FP3
OpenPages Cloud pak for data service version - update to 9.5.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Terracotta - update to 11.1.0
IBM Cognos Controller - update to 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
Library Support for Spring - update to 2.7.29
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.15, 6.4.0.4
StreamSets Data Collector - update to 7.1.0
IBM OpenPages with Watson - addressed in versions 9.0.0.5.7, 9.1.2.1
External References
Related Security Bulletins
- Path traversal in Spring Framework
- IBM Sterling Connect:Direct Web Services update for Spring Framework MVC
- Multiple vulnerabilities in IBM OpenPages for Cloud Pak for Data
- IBM Business Automation Workflow update for Spring Framework MVC
- IBM Watson Speech Services Cartridge update for Spring Framework MVC
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Observability with Instana
- IBM Spectrum Symphony update for Spring Framework MVC
- IBM Controller update for Spring Framework MVC
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for Spring Framework MVC
- Multiple vulnerabilities in IBM Library Support for Spring
- Multiple vulnerabilities in IBM Terracotta
- Multiple vulnerabilities in IBM Process Mining
- IBM StreamSets Data Collector update for Spring Framework MVC
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM DevOps Build
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- Multiple vulnerabilities in Oracle Enterprise Command Center Framework
- Multiple vulnerabilities in IBM Sterling B2B Integrator and IBM Sterling File Gateway
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition