MEDIUM
CVE-2025-48927
CVSS
5.3
KEV
Description
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.
Summary dbcve.org
The TeleMessage service through early May 2025 exposes Spring Boot Actuator's /heapdump endpoint, which allows unauthenticated attackers to download JVM heap dumps containing sensitive memory contents like credentials, session tokens, and application data.
Mitigation
Disable or restrict access to the heap dump endpoint in Spring Boot Actuator configuration, and update TeleMessage to a patched version released after the in-the-wild exploitation.
Weakness (CWE)
CWE-1188
EPSS Score
11.1%
Probability of exploitation in next 30 days
95.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.