IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
[
{
"events": [
{
"introduced": "8.0.302.0"
},
{
"last_affected": "8.0.442.0"
}
]
},
{
"events": [
{
"introduced": "11.0.12.0"
},
{
"last_affected": "11.026.0"
}
]
},
{
"events": [
{
"introduced": "17.0.0.0"
},
{
"last_affected": "17.0.14.0"
}
]
},
{
"events": [
{
"introduced": "21.0.0.0"
},
{
"last_affected": "21.0.6.0"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-2900.json"