Improper verification of cryptographic signature in JSON Web Signatures - CVE-2025-65945

 

Improper verification of cryptographic signature in JSON Web Signatures - CVE-2025-65945

Published: January 19, 2026


Vulnerability identifier: #VU121638
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-65945
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to improper signature verification under specific conditions when using the HS256 algorithm within the jws.createVerify() function. A remote attacker can manipulate header or payload in the HMAC secret lookup routines and bypass authorization checks. 


Affected software

JSON Web Signatures
watsonx.data
Voice Gateway
watsonx Orchestrate Developer Edition
Security QRadar EDR
watsonx Code Assistant On Prem
WatsonX BI Assistant
watsonx.data integration
Maximo Application Suite - Monitor Component
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Application Suite - Edge Data Collector
Developer Hub
IBM App Connect Enterprise
PowerVC
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
Event Streams

How to mitigate CVE-2025-65945

Install updates from vendor's website.

JSON Web Signatures - addressed in versions 3.2.3, 4.0.1
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.18, 1.0.8.24, 1.0.8.29
watsonx Orchestrate Developer Edition - update to 2.3.0
Developer Hub - addressed in versions 1.7.4, 1.8.2
watsonx.data - update to 2.3.1
Security QRadar EDR - update to 3.12.24
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 4.3.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.0
WatsonX BI Assistant - update to 5.3
watsonx.data integration - update to 5.3.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.27, 8.11.25, 9.0.17, 9.1.7
Event Streams - update to 12.2.2
IBM App Connect Enterprise - addressed in versions 12.0.12.21, 13.0.6.0
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - update to 16.1.0.20
Maximo Application Suite - Edge Data Collector - update to 8.11.25

External References

Related Security Bulletins