Improper Check for Unusual or Exceptional Conditions in pip - CVE-2025-8869
Published: November 7, 2025
Vulnerability identifier: #VU118203
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-8869
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists due to improper error handling. A remote attacker can trick the victim into opening a specially crafted data and modify data on the system.
Affected software
pip
watsonx.data
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
DataStage on Cloud Pak for Data
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Siebel CRM Cloud Applications
openEuler
Fedora
IBM Cloud Pak for Business Automation
IBM TXSeries for Multiplatforms
pypy
python3-pip
python2-pip
python-pip-wheel
python-pip-help
python-pip
watsonx.data
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
DataStage on Cloud Pak for Data
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Siebel CRM Cloud Applications
openEuler
Fedora
IBM Cloud Pak for Business Automation
IBM TXSeries for Multiplatforms
pypy
python3-pip
python2-pip
python-pip-wheel
python-pip-help
python-pip
How to mitigate CVE-2025-8869
Install updates from vendor's website.
pip - update to 25.3
watsonx.data - update to 2.3
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
pypy - addressed in versions 7.3.21-8.fc43, 7.3.21-8.fc44, 7.3.21-8.fc45
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix21
python3-pip - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
python2-pip - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15
python-pip-wheel - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
python-pip-help - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
python-pip - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
watsonx.data - update to 2.3
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
pypy - addressed in versions 7.3.21-8.fc43, 7.3.21-8.fc44, 7.3.21-8.fc45
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix21
python3-pip - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
python2-pip - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15
python-pip-wheel - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
python-pip-help - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
python-pip - addressed in versions 20.2.2-13, 20.2.2-14, 20.2.2-15, 21.3.1-12, 21.3.1-13, 21.3.1-14, 23.3.1-7, 23.3.1-9
External References
Related Security Bulletins
- Improper check for unusual or exceptional conditions in pip
- Multiple vulnerabilities in IBM Business Automation Insights
- openEuler 20.03 LTS SP4 update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- Multiple vulnerabilities in IBM Guardium Data Security Center
- openEuler 22.03 LTS SP3 update for python-pip
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for pip
- openEuler 24.03 LTS SP1 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS update for python-pip
- openEuler 24.03 LTS SP2 update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS SP1 update for python-pip
- openEuler 24.03 LTS update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS SP3 update for python-pip
- openEuler 24.03 LTS SP2 update for python-pip
- IBM watsonx.data update for pip
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for pip
- Multiple vulnerabilities in Siebel CRM Cloud Applications
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Fedora 45 update for pypy
- Fedora 44 update for pypy
- Fedora 43 update for pypy
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms