Information Exposure Through an Error Message in jackson-core - CVE-2025-49128
Published: October 6, 2025
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability in jackson-core's `JsonLocation._appendSourceDesc` method allows up to 500 bytes of unintended memory content to be included in exception messages. When parsing JSON from a byte array with an offset and length, the exception message incorrectly reads from the beginning of the array instead of the logical payload start. This results in possible information disclosure in systems using pooled or reused buffers, like Netty or Vert.x. A local user can gain unauthorized access to sensitive information on the system.
Affected software
Operations Analytics - Log Analysis
Cloudera Observability with IBM
Knowledge Catalog Premium Cartridge
Maximo Application Suite - IoT Component
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Enterprise Manager Base Platform
Financial Transaction Manager for ACH Services and Check Services
How to mitigate CVE-2025-49128
Operations Analytics - Log Analysis - update to 1.3.8.4
Netcool Operations Insight - update to 1.6.15
Cloudera Observability with IBM - update to 3.6.2
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Maximo Application Suite - IoT Component - addressed in versions 8.7.28, 8.8.24, 9.0.14, 9.1.5
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
External References
Related Security Bulletins
- Information exposure through an error message in Jackson-core
- IBM Watson Discovery update for Jackson-core
- Information Exposure Through an Error Message in Enterprise Manager Base Platform
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem