3.7
CVE-2025-2529
- EPSS 0.05%
- Veröffentlicht 15.10.2025 15:29:04
- Zuletzt bearbeitet 14.01.2026 20:40:03
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Terracotta Version >= 10.15.0 < 10.15.0.23
Ibm ≫ Terracotta Version >= 11.1.0 < 11.1.0.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.147 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| psirt@us.ibm.com | 2.9 | 1.4 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-228 Improper Handling of Syntactically Invalid Structure
The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.