CVE-2025-5115 – Oracle
“One update can close hundreds of attack paths when it reaches every critical component.”
This security release addresses vulnerabilities across a broad range of open-source and commercial software components used throughout enterprise environments. The update includes multiple Critical, High, Medium, and Low severity vulnerabilities affecting web frameworks, databases, messaging platforms, networking libraries, cryptographic libraries, virtualization software, operating system components, logging frameworks, and developer tools. The fixes improve memory safety, input validation, authentication, authorization, bounds checking, cryptographic handling, and resource management while reducing the overall attack surface.
The release includes several Critical vulnerabilities with confirmed CVSS scores of 9.8, 9.4, and 9.1, together with numerous High severity vulnerabilities ranging from 7.0 to 8.9. Several entries include verified public proof-of-concept availability, while no active exploitation is identified in the provided data.
CVE LIST:
CVE-2024-28168 CVE-2024-29371 CVE-2024-37997 CVE-2024-47554 CVE-2024-7254 CVE-2025-13465 CVE-2025-27821 CVE-2025-48924 CVE-2025-5115 CVE-2025-54920 CVE-2025-67030 CVE-2025-67721 CVE-2025-67735 CVE-2025-68161 CVE-2025-7962 CVE-2025-8916 CVE-2026-1002 CVE-2026-10879 CVE-2026-1225 CVE-2026-21452 CVE-2026-22029 CVE-2026-2332 CVE-2026-23865 CVE-2026-24281 CVE-2026-25526 CVE-2026-25639 CVE-2026-27727 CVE-2026-28387 CVE-2026-33557 CVE-2026-33871 CVE-2026-34478 CVE-2026-34481 CVE-2026-35554 CVE-2026-41044 CVE-2026-4176 CVE-2026-43512 CVE-2026-46975 CVE-2026-47022 CVE-2026-47038 CVE-2026-47039 CVE-2026-47040 CVE-2026-47045 CVE-2026-47046 CVE-2026-47060 CVE-2026-47061 CVE-2026-4738 CVE-2026-54285 CVE-2026-54513 CVE-2026-54515 CVE-2026-54518 CVE-2026-60156 CVE-2026-60157 CVE-2026-60172 CVE-2026-60175 CVE-2026-60394 CVE-2026-60395 CVE-2026-60396 CVE-2026-60397 CVE-2026-60398 CVE-2026-60399 CVE-2026-60400 CVE-2026-60630 CVE-2026-61211 CVE-2026-7210 CVE-2026-7383
Vulnerability Coverage by Product / Subsystem
Operating Systems
Linux Kernel
Oracle Database Server
Oracle Net Services
GoldenGate Stream Analytics
Application Servers & Web Platforms
Apache Tomcat
Apache ActiveMQ
Apache Kafka
Apache Kafka Clients
Apache Spark
Eclipse Jetty
React Router
Apache ZooKeeper
Databases
Oracle Database Server
MongoDB Server
Networking & Communication
Netty
OpenSSL
Apache Hadoop HDFS Native Client
msgpack-java
Eclipse Vert.x
Jakarta Mail
axios
Logging & Monitoring
Apache Log4j Core
Apache Log4j JSON Template Layout
OpenTelemetry JavaScript
Serialization / Data Processing
Protocol Buffers
Jackson Databind
MessagePack Java
Apache XML Graphics FOP
Apache Commons IO
Apache Commons Lang
JinJava
Cryptography & Security Libraries
BC Java
OpenSSL
Logback-core
jose4j
mchange-commons-java
JavaScript / Web Libraries
Lodash
axios
React Router
Developer & Build Tools
Plexus Utils
Aircompressor
GDAL
Perl
FreeType
Messaging & Middleware
Apache Kafka
Apache ActiveMQ
Netty
Visualization & Engineering Software
Siemens JT Open
JT2Go
PLM XML SDK
Teamcenter Visualization
Key Security Themes
Remote code execution prevention
Authentication and authorization hardening
Memory corruption mitigation
Use-after-free and buffer overflow fixes
Bounds validation improvements
Deserialization security
XML and request parsing protections
Denial-of-service resilience
Information disclosure prevention
Race condition and concurrency fixes
Multiple Critical vulnerabilities were addressed across widely deployed enterprise software.
Memory safety, authentication, deserialization, and input validation represent the primary security improvements.
Several vulnerabilities have publicly available proof-of-concept code, increasing the urgency of patch deployment.
Applying these updates significantly reduces risk across enterprise application stacks and infrastructure.
Key Details
- Affected Product
- Eclipse Jetty
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-400