vulnerability

Red Hat: CVE-2025-2900: ibm-semeru: IBM Semeru Runtime denial of service (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
May 14, 2025
Added
Jan 27, 2026
Modified
Jan 27, 2026

Description

IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.

Solutions

redhat-upgrade-java-21-ibm-semeru-certified-jdkredhat-upgrade-java-21-ibm-semeru-certified-jdk-develredhat-upgrade-java-21-ibm-semeru-certified-jdk-headlessredhat-upgrade-java-21-ibm-semeru-certified-jdk-jmodsredhat-upgrade-java-21-ibm-semeru-certified-jdk-src
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.