Resource exhaustion in Apache Struts - CVE-2025-64775
Published: December 1, 2025 / Updated: December 4, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling multipart requests. A remote attacker can consume all disk space on the system and perform a denial of service (DoS) attack.
Affected software
Library Support for Struts
SAP BusinessObjects Business Intelligence suite
Crowd Data Center
IBM Tivoli Netcool/OMNIbus WebGUI
Bamboo Server
Bamboo Data Center
Infrastructure Technology
Crowd Server
How to mitigate CVE-2025-64775
Crowd Server - update to 7.1.3
Crowd Data Center - update to 7.1.3
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.40
Bamboo Server - addressed in versions 9.6.21, 10.2.13, 12.1.0
Bamboo Data Center - addressed in versions 9.6.21, 10.2.13, 12.1.0
External References
Related Security Bulletins
- Denial of service in Apache Struts
- Crowd Data Center and Server update for org.apache.struts:struts2-core
- Multiple vulnerabilities in IBM Library Support for Struts
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- SAP BusinessObjects Business Intelligence Platform update for Apache Struts
- Multiple vulnerabilities in Infrastructure Technology
- Bamboo Data Center update for Apache Struts