CVE-2025-48927: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48927?
CVE-2025-48927 is considered a critical vulnerability due to exposed sensitive data through the heap dump endpoint.
How do I fix CVE-2025-48927?
To fix CVE-2025-48927, ensure that the Spring Boot Actuator's heap dump endpoint is disabled or properly secured.
What systems are affected by CVE-2025-48927?
CVE-2025-48927 affects the TeleMessage service versions up to and including 2025-05-05 that use Spring Boot Actuator.
What are the potential impacts of exploiting CVE-2025-48927?
Exploitation of CVE-2025-48927 can lead to unauthorized access to sensitive application data including the memory state of the application.
When was CVE-2025-48927 first exploited?
CVE-2025-48927 was first exploited in the wild in May 2025.