Loading
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
Use CWE-528, Smarsh vendor hub and Telemessage product page to widen CVE-2025-48928 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-48927, CVE-2025-47730 and CVE-2025-48926 for nearby disclosures in the same product family.