Files or Directories Accessible to External Parties in Vert.x-Web - CVE-2025-11965

 

Files or Directories Accessible to External Parties in Vert.x-Web - CVE-2025-11965

Published: October 23, 2025


Vulnerability identifier: #VU117583
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11965
CWE-ID: CWE-552
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the files or directories accessible to external parties in the hidden file protection feature of "StaticHandler" when "setIncludeHidden(false)" is configured. A remote attacker can gain access to sensitive information on the system.


Affected software

Vert.x-Web
Event Processing
IBM Business Automation Manager Open Editions
IBM Event Endpoint Management
AMQ Streams

How to mitigate CVE-2025-11965

Install updates from vendor's website.

Vert.x-Web - addressed in versions 4.5.22, 5.0.5
Event Processing - update to 1.4.7
IBM Business Automation Manager Open Editions - update to 9.3.1
IBM Event Endpoint Management - update to 11.7.2
AMQ Streams - update to 3.1.0

External References

Related Security Bulletins