Input validation error in JDBC Driver for SQL Server - CVE-2025-59250
Published: October 15, 2025
Vulnerability identifier: #VU117197
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59250
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in JDBC Driver for SQL Server. A remote attacker can trick a victim into connecting to a malicious server and perform spoofing attack.
Affected software
JDBC Driver for SQL Server
Atlassian Fisheye
Crucible Server
IBM Sterling B2B Integrator
IBM Cloud Pak for Business Automation
Splunk AppDynamics Database Agent
IBM Maximo Application Suite - Manage Component
IBM Sterling File Gateway
IBM Business Automation Manager Open Editions
IBM License Metric Tool
Oracle GoldenGate Big Data and Application Adapters
Atlassian Fisheye
Crucible Server
IBM Sterling B2B Integrator
IBM Cloud Pak for Business Automation
Splunk AppDynamics Database Agent
IBM Maximo Application Suite - Manage Component
IBM Sterling File Gateway
IBM Business Automation Manager Open Editions
IBM License Metric Tool
Oracle GoldenGate Big Data and Application Adapters
How to mitigate CVE-2025-59250
Install updates from vendor's website.
Atlassian Fisheye - update to 4.9.5
Crucible Server - update to 4.9.5
IBM Sterling B2B Integrator - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Business Automation Manager Open Editions - update to 9.3.1
IBM License Metric Tool - update to 9.2.42
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
Splunk AppDynamics Database Agent - update to 26.1.0
IBM Maximo Application Suite - Manage Component - update to 9.1.11
Crucible Server - update to 4.9.5
IBM Sterling B2B Integrator - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Business Automation Manager Open Editions - update to 9.3.1
IBM License Metric Tool - update to 9.2.42
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
Splunk AppDynamics Database Agent - update to 26.1.0
IBM Maximo Application Suite - Manage Component - update to 9.1.11
External References
Related Security Bulletins
- Spoofing vulnerability in Microsoft JDBC Driver for SQL Server
- Multiple vulnerabilities in IBM License Metric Tool
- Atlassian Crucible and Fisheye update for MSSQL driver
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Oracle GoldenGate Big Data and Application Adapters
- Splunk AppDynamics Database Agent update for third-party components
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM Maximo Application Suite - Manage Component update for JDBC Driver for SQL Server
- IBM Sterling B2B Integrator and IBM Sterling File Gateway update for JDBC Driver for SQL Server