Executive brief
TeleMessage TM SGNL, a secure messaging service used for enterprise communications, contains a vulnerability that exposes sensitive memory contents. An attacker could access a 'core dump' file containing the heap memory of the application, which may include user passwords previously sent over the network. This flaw has been observed being exploited in the wild, potentially leading to unauthorized account access and the compromise of private communications.
Technical details
TeleMessage TM SGNL is a JSP-based application that suffers from an exposure of sensitive information via core dump files (CWE-528/CWE-552). The application's heap content, which is equivalent to a core dump, is accessible to unauthorized control spheres. This memory dump can contain plaintext passwords that were previously transmitted over HTTP. While the CVSS vector suggests local access (AV:L), the vulnerability has been confirmed as exploited in the wild as of May 2025. Organizations are advised to apply vendor-provided mitigations or discontinue use if patches are unavailable.
Affected products
- TeleMessage (Smarsh) TM SGNL (TeleMessage) through 2025-05-05
Timeline
- 2025-05-05: other: Vulnerability confirmed present in service through this date
- 2025-05-28: disclosed: CVE assigned and initial details released
- 2025-05-01: exploited: Exploited in the wild in May 2025
- 2025-07-01: kev added: Added to CISA KEV catalog