Junglewise Threat Intelligence

CVE-2025-48927: TeleMessage TM SGNL insecure default configuration in Spring Boot Actuator

CVE-2025-48927 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2025-07-01

Technologies: Telemessage TM SGNL. Vendors: Telemessage.

Executive brief

TeleMessage, a secure messaging service used for enterprise compliance, was found to have an insecurely configured server component. This flaw allowed unauthorized individuals to download a 'heap dump,' which is a snapshot of the application's memory that can contain sensitive information such as user messages, credentials, or encryption keys. This vulnerability has been exploited in the wild, potentially compromising the confidentiality of communications for affected organizations.

Technical details

The TeleMessage service (TM SGNL) through 2025-05-05 was configured with an insecure default for the Spring Boot Actuator component. Specifically, the '/heapdump' URI was left exposed to the public internet without authentication (CWE-1188). An unauthenticated remote attacker can request this endpoint to download a full JVM heap dump. This snapshot of the application's memory can be analyzed offline to extract sensitive data, including session tokens, environment variables, and potentially decrypted message content. This vulnerability is confirmed to have been exploited in the wild.

Affected products

  • TeleMessage (Smarsh) TM SGNL (TeleMessage) through 2025-05-05

Timeline

  • 2025-05-05: other: Vulnerability identified in service version through this date
  • 2025-05-28: disclosed: CVE published and initial disclosure via media reports
  • 2025-07-01: kev added: CISA added to Known Exploited Vulnerabilities catalog

Related threats