CVE-2025-33076

8.8

IBM · Engineering Systems Design Rhapsody

IBM Engineering Systems Design Rhapsody is vulnerable to a stack-based buffer overflow due to improper bounds checking, which allows a local attacker to execute arbitrary code.

Executive summary

A stack-based buffer overflow in IBM Engineering Systems Design Rhapsody versions 9.0.2, 10.0, and 10.0.1 poses a high risk of arbitrary code execution by local attackers.

Vulnerability

The application suffers from a stack-based buffer overflow (CWE-119) caused by insufficient bounds checking on input. While the CVSS vector indicates network access is possible, the vulnerability requires low privileges, meaning an authenticated local user can trigger the overflow to execute arbitrary code.

Business impact

The ability for a local attacker to execute arbitrary code represents a significant threat to system integrity and confidentiality. Given the CVSS score of 8.8, this vulnerability is classified as High severity, as it could lead to full system compromise, unauthorized data access, or the deployment of persistent malware within the engineering environment.

Remediation

Immediate Action: Upgrade to the provided fixed versions: IBM Engineering Systems Design Rhapsody 9.0.2 iFix004, 10.0 iFix002, or 10.0.1 iFix003.

Proactive Monitoring: Review system and application access logs for unusual command execution patterns or abnormal process behavior originating from standard user accounts.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced to limit the impact of a potential compromise by preventing non-administrative users from accessing sensitive system memory areas.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to prevent potential system-level exploitation. Organizations should prioritize the deployment of the specified iFix patches across all affected Rhapsody instances to eliminate the buffer overflow risk and ensure the continued security of the engineering environment.

More IBM CVEs

Sources