SB2025102729 - IBM Control Center update for Spring Security



SB2025102729 - IBM Control Center update for Spring Security

Published: October 27, 2025

Security Bulletin ID SB2025102729
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper authorization (CVE-ID: CVE-2025-41232)

The vulnerability allows a remote attacker to compromise the affected application.

The vulnerability exists due to an error in Spring Security Aspects, that may not correctly locate method security annotations on private methods. A remote non-authenticated attacker can bypass authorization checks and gain unauthorized access to the application. 

The vulnerability affects system that:

  1. use @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, and
  2. have Spring Security method annotations on a private method



Remediation

Install update from vendor's website.