Protection Mechanism Failure in Spring Framework - CVE-2025-41249

 

Protection Mechanism Failure in Spring Framework - CVE-2025-41249

Published: September 16, 2025


Vulnerability identifier: #VU115573
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41249
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information. 

The vulnerability exists due to the annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. A remote attacker can gain access to sensitive information. 


Affected software

Spring Framework
Netezza Appliance
Storage Defender Copy Data Management
DB2 Data Management Console
Guardium Data Security Center (GDSC)
OpenPages for IBM Cloud Pak for Data
Oracle Healthcare Master Person Index
UrbanCode Build
DevOps
Oracle Financial Services Analytical Applications Infrastructure
OpenPages Cloud pak for data service version
IBM Business Automation Manager Open Editions
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Oracle Retail Service Backbone
Business Automation Insights
Maximo Application Suite - IoT Component
IBM OpenPages with Watson
IBM Observability with Instana
IBM Process Mining
Bitbucket Data Center
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
Crowd Data Center
Oracle Communications Network Integrity
Confluence Data Center
IBM Rational Build Forge
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Model Management and Governance
Jira Software Data Center
Jira Service Management Data Center
Jira Service Management Server
Oracle Middleware Common Libraries and Tools
Oracle WebCenter Forms Recognition
Oracle Banking Trade Finance
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Network Exposure Function
Red Hat OpenShift Dev Spaces
IBM Sterling Connect:Direct Web Services
Oracle Financial Services Compliance Studio
Oracle Banking Corporate Lending Process Management
Oracle Banking Virtual Account Management
Oracle Banking Branch
Oracle Banking Origination
Oracle Banking Cash Management
Oracle Retail Bulk Data Integration
Bitbucket Server
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Primavera Gateway
Communications Unified Assurance
IBM Sterling File Gateway
Confluence Server
RSA Authentication Manager
Oracle Banking Corporate Lending
Jira Software Server
Oracle Commerce Guided Search
Oracle Commerce Platform
Oracle Retail Financial Integration
IBM InfoSphere Information Server
Oracle Communications BRM - Elastic Charging Engine
Identity Manager
Oracle Documaker
Oracle Enterprise Manager for Fusion Middleware
Oracle Retail Integration Bus
Primavera Unifier
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Library Support for Spring
Red Hat Camel for Spring Boot

How to mitigate CVE-2025-41249

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.45, 6.1.23, 6.2.11
Netezza Appliance - update to 1.0.0.1
IBM Observability with Instana - update to 1.0.309
IBM Process Mining - update to 2.1.0
Storage Defender Copy Data Management - update to 2.3.1.0
DB2 Data Management Console - update to 3.1.13.2
Bitbucket Data Center - addressed in versions 8.19.26, 9.4.15, 10.0.1
Bitbucket Server - addressed in versions 8.19.26, 9.4.15, 10.0.1
Guardium Data Security Center (GDSC) - update to 3.8.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
OpenPages for IBM Cloud Pak for Data - update to 5.2.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
IBM Sterling Control Center - addressed in versions 6.3.1.0.6, 6.4.0.0.2, 6.4.1.0.1
Crowd Data Center - update to 7.0.2
DevOps - update to 7.1.0.2
Confluence Server - addressed in versions 9.2.14, 10.2.3
Confluence Data Center - addressed in versions 9.2.14, 10.2.3
RSA Authentication Manager - update to 8.9 Patch 1
IBM Rational Build Forge - update to 8.0.0.29
OpenPages Cloud pak for data service version - update to 9.5.2
IBM Business Automation Manager Open Editions - update to 9.3.1
Jira Software Server - update to 11.2.0
Jira Software Data Center - update to 11.2.0
Jira Service Management Data Center - update to 11.2.0
Jira Service Management Server - update to 11.2.0
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
Library Support for Spring - update to 2.7.29
Red Hat OpenShift Dev Spaces - update to 3.24.0
Red Hat Camel for Spring Boot - update to 4.10.7
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.15, 6.4.0.4
Maximo Application Suite - IoT Component - addressed in versions 8.7.26, 8.8.22, 9.0.12, 9.1.3
IBM OpenPages with Watson - addressed in versions 9.0.0.5.7, 9.1.2.1

External References

Related Security Bulletins