Missing Encryption of Sensitive Data in pyjwt - CVE-2025-45768

 

Missing Encryption of Sensitive Data in pyjwt - CVE-2025-45768

Published: September 17, 2025


Vulnerability identifier: #VU115711
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-45768
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the system.

The vulnerability exists due to weak encryption. A remote attacker can gain unauthorized access to the system.


Affected software

pyjwt
Maximo Application Suite Ai Service
IBM Fusion HCI
IBM Watson Discovery for IBM Cloud Pak for Data

How to mitigate CVE-2025-45768

Install updates from vendor's website.

IBM Fusion HCI - update to 2.11.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.2
Maximo Application Suite Ai Service - update to 9.1.3

External References

Related Security Bulletins