Improper Handling of Unexpected Data Type in on-headers - CVE-2025-7339

 

Improper Handling of Unexpected Data Type in on-headers - CVE-2025-7339

Published: August 22, 2025


Vulnerability identifier: #VU114392
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7339
CWE-ID: CWE-241
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can inadvertently modify response headers when an array is passed to `response.writeHead()`


Affected software

on-headers
watsonx Orchestrate Developer Edition
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
WatsonX BI Assistant
Db2 Big SQL
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Communications Unified Assurance
Event Streams
IBM Cognos Controller
IBM API Connect
IBM DataPower Gateway
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2025-7339

Install updates from vendor's website.

on-headers - update to 1.1.0
watsonx Orchestrate Developer Edition - update to 1.13.0
Guardium Data Security Center (GDSC) - update to 3.8.8
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.2
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
WatsonX BI Assistant - update to 5.2.1
Db2 Big SQL - update to 8.2
Maximo Application Suite - Monitor Component - addressed in versions 8.10.25, 8.11.23, 9.0.15, 9.1.5
Event Streams - update to 12.2.2
IBM API Connect - update to 10.0.8.5
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7, 10.6.5.0
DevOps Test Performance - update to 11.0.8
Business Automation Insights - update to 25.0.0.0.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.20.14
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001

External References

Related Security Bulletins