IBM Support

Security Bulletin: Impacted IBM Optim 1.0.0, 1.1.0 and 1.2.0  by vulnerabilities in plexus-utils, OpenSSL, jose4j, Go net/url, and Apache Hadoop

Security Bulletin


Summary

IBM Optim versions 1.0.0, 1.1.0, and 1.2.0 include open-source packages plexus-utils, OpenSSL, jose4j, Go net/url, and Apache Hadoop that are affected by five vulnerabilities ranging from high to medium-high severity, including path traversal, stack buffer overflow, denial-of-service via decompression bomb, and out-of-bounds write. IBM Optim 2.0.0 resolves all of these vulnerabilities by upgrading the affected open-source dependencies to fixed versions.

Vulnerability Details

CVEID:   CVE-2025-67030
DESCRIPTION:   Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   NVD
CVSS Base score:   8.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

CVEID:   CVE-2025-15467
DESCRIPTION:   Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
CWE:   CWE-787: Out-of-bounds Write
CVSS Source:   CISA ADP
CVSS Base score:   8.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

CVEID:   CVE-2024-29371
DESCRIPTION:   In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
CWE:   CWE-1259: Improper Restriction of Security Token Assignment
CVSS Source:   CISA ADP
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:   CVE-2025-61726
DESCRIPTION:   The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
CWE:   CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source:   CISA ADP
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:   CVE-2025-27821
DESCRIPTION:   Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CWE:   CWE-787: Out-of-bounds Write
CVSS Source:   CISA ADP
CVSS Base score:   7.3
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s)Version(s)
IBM Optim1.0.0
IBM Optim1.1.0
IBM Optim1.2.0

Remediation/Fixes

Move to IBM Optim 2.0.0 IBM

Optim 2.0.0 resolves all five vulnerabilities by upgrading the affected open-source dependencies.

plexus-utils has been upgraded to version 4.0.3 or later. This version corrects the directory traversal flaw in the extractFile method of org.codehaus.plexus.util.Expand, preventing path escape during archive extraction (CVE-2025-67030).

OpenSSL package has been upgraded to a fixed version.

jose4j has been upgraded to version 0.9.6 or later. This version enforces limits on decompression output during JWE token processing, preventing the denial-of-service condition caused by high-ratio compressed payloads (CVE-2024-29371).

Go has been upgraded to version 1.25.6 or later (or 1.24.12 or later on the 1.24 release line). The updated net/url package enforces a limit on the number of query parameters parsed by net/http.Request.ParseForm, preventing excessive memory consumption (CVE-2025-61726).

Apache Hadoop has been upgraded to version 3.4.2 or later. This version resolves the out-of-bounds write vulnerability in the HDFS native client (CVE-2025-27821).

Available from https://www.ibm.com/software/passportadvantage/pao-customer

 

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

21 Sep 2026: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY. In addition to other efforts to address potential vulnerabilities, IBM periodically updates the record of components contained in our product offerings. As part of that effort, if IBM identifies previously unidentified packages in a product/service inventory, we address relevant vulnerabilities regardless of CVE date. Inclusion of an older CVEID does not demonstrate that the referenced product has been used by IBM since that date, nor that IBM was aware of a vulnerability as of that date. We are making clients aware of relevant vulnerabilities as we become aware of them. "Affected Products and Versions" referenced in IBM Security Bulletins are intended to be only products and versions that are supported by IBM and have not passed their end-of-support or warranty date. Thus, failure to reference unsupported or extended-support products and versions in this Security Bulletin does not constitute a determination by IBM that they are unaffected by the vulnerability. Reference to one or more unsupported versions in this Security Bulletin shall not create an obligation for IBM to provide fixes for any unsupported or extended-support products or versions.

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSAB4O","label":"IBM Optim Test Data Management"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF043","label":"Red Hat"}],"Version":"1.0.0, 1.1.0, 1.2.0","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}},{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSNJ5KN","label":"IBM Optim Data Privacy"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF043","label":"Red Hat"}],"Version":"1.0.0, 1.1.0, 1.2.0","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}},{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSL5YG","label":"IBM Optim Archive"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF043","label":"Red Hat"}],"Version":"1.0.0, 1.1.0, 1.2.0","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Document Information

Modified date:
21 September 2026

Initial Publish date:
21 September 2026

UID

ibm17288673