CVE-2025-2900: IBM Semeru Runtime
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
Affected products
- IBM Semeru Runtime: from 8.0.302.0, up to and including 8.0.442.0; from 11.0.12.0, up to and including 11.026.0; from 17.0.0.0, up to and including 17.0.14.0; from 21.0.0.0, up to and including 21.0.6.0
Published 2025-05-14. Last modified 2026-06-17.