CVE-2025-48927
28.05.2025, 17:15
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.Enginsight
Vendor | Product | Version |
---|---|---|
smarsh | telemessage | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
Vulnerability Media Exposure