CVE-2025-2529: IBM Terracotta denial of service
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Terracottato a version that resolves this vulnerability.Fixed in 10.15.0Patch Fix 24 - Upgrade
Upgrade
IBM Terracottato a version that resolves this vulnerability.Fixed in 11.1.0Patch Fix 6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2529?
CVE-2025-2529 has a moderate severity level due to its impact on cache-write performance when exposed to malicious external inputs.
How do I fix CVE-2025-2529?
To fix CVE-2025-2529, ensure that all cache keys used with Ehcache are properly filtered and salted to prevent performance degradation.
Which versions of Ehcache are affected by CVE-2025-2529?
CVE-2025-2529 affects all versions of IBM Ehcache 3.x.
What is the impact of CVE-2025-2529 on applications?
The impact of CVE-2025-2529 is a significant degradation in cache-write performance in applications utilizing unfiltered cache keys.
Does CVE-2025-2529 affect IBM Terracotta?
CVE-2025-2529 primarily affects IBM Ehcache, but it may indirectly impact applications using Terracotta if they rely on the affected versions of Ehcache.