CVE-2025-2529 Details
Description
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
A denial-of-service vulnerability has been identified in the Ehcache 3.x component of IBM Terracotta, specifically in versions 10.15.0 prior to 10.15.0 Fix 23 and 11.1.0 prior to 11.1.0 Fix 5. This vulnerability can degrade cache-write performance in applications that use cache keys from external parties without proper filtering or salting.
Users are advised to upgrade to IBM Terracotta 11.1.0 Fix 6 or later, or IBM Terracotta 10.15.0 Fix 24 or later. These updates can be downloaded via the IBM webMethods Update Manager.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7247977 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-228 | Improper Handling of Syntactically Invalid Structure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm terracotta | >= 10.15.0, < 10.15.0.23 >= 11.1.0, < 11.1.0.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Oct 15, 2025 | New CVE Received | [email protected] |