vulnerability
Red Hat: CVE-2025-2900: ibm-semeru: IBM Semeru Runtime denial of service (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | May 14, 2025 | Jan 27, 2026 | Jan 27, 2026 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
May 14, 2025
Added
Jan 27, 2026
Modified
Jan 27, 2026
Description
IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
Solutions
redhat-upgrade-java-21-ibm-semeru-certified-jdkredhat-upgrade-java-21-ibm-semeru-certified-jdk-develredhat-upgrade-java-21-ibm-semeru-certified-jdk-headlessredhat-upgrade-java-21-ibm-semeru-certified-jdk-jmodsredhat-upgrade-java-21-ibm-semeru-certified-jdk-src
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.