Input validation error in cipher-base - CVE-2025-9287

 

Input validation error in cipher-base - CVE-2025-9287

Published: September 18, 2025


Vulnerability identifier: #VU115762
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-9287
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate data or perform a denial of service attack.

The vulnerability exists due to a missing type check of untrusted input. A remote attacker can manipulate data representation within the application, which can lead to denial of service conditions or various calculation errors when handling private keys or hashes. 


Affected software

cipher-base
Debian Linux
Ubuntu
Crowd Server
Crowd Data Center
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
Jira Service Management Server
Jira Software Data Center
Jira Service Management Data Center
OpenShift Pipelines
Jira Software Server
node-cipher-base (Ubuntu package)
node-cipher-base (Debian package)
QRadar Suite
Splunk Security Orchestration, Automation and Response (SOAR)
Multicluster Engine for Kubernetes
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge

How to mitigate CVE-2025-9287

Install updates from vendor's website.

cipher-base - update to 1.0.5
Crowd Server - update to 7.1.2
Crowd Data Center - update to 7.1.2
IBM Cloud Pak for Security - update to 1.11.9.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.12.5, 2.13.5
Jira Software Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Software Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
node-cipher-base (Ubuntu package) - addressed in versions 1.0.4-1ubuntu0.1~esm2, 1.0.4-4ubuntu0.1~esm2, 1.0.4-6+deb13u1ubuntu0.22.04.1, 1.0.4-6+deb13u1ubuntu0.24.04.1, 1.0.4-6+deb13u1ubuntu0.25.04.1
node-cipher-base (Debian package) - addressed in versions 1.0.4-6+deb12u1, 1.0.4-6+deb13u1
QRadar Suite - update to 1.11.9.0
OpenShift Pipelines - update to 1.19.4
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.7.6
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0

External References

Related Security Bulletins