CVE Database
/

CVE-2025-2529

Back to search

CVE-2025-2529

Published: Oct 15, 2025

Modified: Oct 16, 2025

PUBLISHED

CVSS v3.1

2.9

LOW

Description

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.

VendorProductVersions

IBM

Terracotta

affected
10.15.0 - <= 10.15.0 IF23
affected
11.1.0 - <= 11.1.0 IF5

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector

Local

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now