MEDIUM

CVE-2025-48927

Smarsh Telemessage 2025-05-28 CVSS v3.1
CVSS
5.3
KEV

Description

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

Summary dbcve.org

The TeleMessage service through early May 2025 exposes Spring Boot Actuator's /heapdump endpoint, which allows unauthenticated attackers to download JVM heap dumps containing sensitive memory contents like credentials, session tokens, and application data.

Mitigation

Disable or restrict access to the heap dump endpoint in Spring Boot Actuator configuration, and update TeleMessage to a patched version released after the in-the-wild exploitation.

Weakness (CWE)

CWE-1188

EPSS Score

11.1%
Probability of exploitation in next 30 days
95.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE