CVE-2022-25647Disclosure(debian / active_iq_unified_manager)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian active_iq_unified_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • debian_linux
  • financial_services_crime_and_compliance_management_studio
  • graalvm

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
active_iq_unified_managerdebian_linuxfinancial_services_crime_and_compliance_management_studiograalvmgsonretail_order_broker

11 versions affected across 6 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 104-21
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Tedsig42@Tedsig42
    Disclosure

    Found a bypass in @Google fix for CVE-2022-25647. They patched 2 methods. Left 2 others wide open. Reported it. Got closed 3 times. Pushed back each time. Finally accepted. Lesson: Don't just look at what gets fixed. Look at what gets missed. Full writeup in comment. https://t.co/KTV2grDbQ1

    Post summary

    The post details how Google patched only part of the fixes for CVE‑2022‑25647, exposing remaining vulnerable methods, and highlights the overlooked patches in a disclosure write‑up.

    1102043
    93 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSdebiandebian_linux9.0--
Appgooglegson---
Appnetappactive_iq_unified_manager-linux-
Appnetappactive_iq_unified_manager-vmware_vsphere-
Appnetappactive_iq_unified_manager-windows-
Apporaclefinancial_services_crime_and_compliance_management_studio8.0.8.2.0--
Apporaclefinancial_services_crime_and_compliance_management_studio8.0.8.3.0--
Apporaclegraalvm20.3.6--
Apporaclegraalvm21.3.2--
Apporaclegraalvm22.1.0--
Apporacleretail_order_broker18.0--
Apporacleretail_order_broker19.1--

Explore more