Information Exposure Through Timing Discrepancy in SCRAM - CVE-2025-59432

 

Information Exposure Through Timing Discrepancy in SCRAM - CVE-2025-59432

Published: October 20, 2025


Vulnerability identifier: #VU117375
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2025-59432
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exist due to timing discrepancy when using Arrays.equals to compare secret values such as client proofs and server signatures. A remote attacker can perform a timing side-channel attack and gain access to sensitive information. 


Affected software

SCRAM
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Server Applications Module
openSUSE Leap
openEuler
Enterprise Build of Quarkus
ongres-scram
ongres-scram-parent
ongres-scram-help
ongres-scram-client
ongres-scram-javadoc

How to mitigate CVE-2025-59432

Install updates from vendor's website.

SCRAM - update to 3.2
Enterprise Build of Quarkus - update to 3.27.2
ongres-scram - addressed in versions 2.1-2, 2.1-3
ongres-scram-parent - addressed in versions 2.1-2, 2.1-3
ongres-scram-help - addressed in versions 2.1-2, 2.1-3
ongres-scram-client - addressed in versions 2.1-2, 2.1-3
ongres-scram-client - update to 2.1-150400.8.5.1
ongres-scram-parent - update to 2.1-150400.8.5.1
ongres-scram - update to 2.1-150400.8.5.1
ongres-scram-javadoc - update to 2.1-150400.8.5.1

External References

Related Security Bulletins