IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-14907 IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
Fixes

Solution

Remediation/Fixes 8.0.452.0 11.0.27.0 17.0.15.0 21.0.7.0 IBM Semeru Runtime releases can be downloaded from the GitHub repositories for Semeru 8, Semeru 11, Semeru 17, and Semeru 21 and from the IBM Semeru Developer Center. IBM customers requiring an update for an SDK shipped with an IBM product should contact IBM support, and/or refer to the appropriate product security bulletin.


Workaround

No workaround given by the vendor.

History

Tue, 19 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:semeru_runtime:*:*:*:*:*:*:*:*

Thu, 22 May 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10.0
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics threat_severity

None

threat_severity

Important


Wed, 14 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 May 2025 19:00:00 +0000

Type Values Removed Values Added
Description IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
Title IBM Semeru Runtime denial of service
First Time appeared Ibm
Ibm semeru Runtime
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:semeru_runtime:11.0.12.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:11.0.26.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:17.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:17.0.14.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:21.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:21.0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:8.0.302.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:semeru_runtime:8.0.442.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm semeru Runtime
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-28T14:12:21.020Z

Reserved: 2025-03-28T02:06:38.367Z

Link: CVE-2025-2900

cve-icon Vulnrichment

Updated: 2025-05-14T19:43:15.914Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-14T19:15:52.690

Modified: 2025-08-19T19:14:18.293

Link: CVE-2025-2900

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-14T18:50:27Z

Links: CVE-2025-2900 - Bugzilla

cve-icon OpenCVE Enrichment

No data.